Apache

Apache-airflow-providers-fab

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 16.09.2026 09:12:51
  • Zuletzt bearbeitet 18.09.2026 14:29:43

Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different cli...

  • EPSS 0.25%
  • Veröffentlicht 16.09.2026 09:09:07
  • Zuletzt bearbeitet 18.09.2026 14:28:10

Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, unexpired toke...

  • EPSS 0.2%
  • Veröffentlicht 16.09.2026 09:05:42
  • Zuletzt bearbeitet 18.09.2026 14:29:11

Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full acces...

  • EPSS 0.2%
  • Veröffentlicht 16.09.2026 09:00:38
  • Zuletzt bearbeitet 18.09.2026 14:28:43

Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session against th...

  • EPSS 0.18%
  • Veröffentlicht 08.09.2026 16:47:48
  • Zuletzt bearbeitet 18.09.2026 14:25:21

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Beca...

  • EPSS 0.68%
  • Veröffentlicht 29.07.2026 08:35:37
  • Zuletzt bearbeitet 16.09.2026 15:17:39

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an ar...

  • EPSS 0.36%
  • Veröffentlicht 13.07.2026 15:05:21
  • Zuletzt bearbeitet 16.09.2026 15:17:39

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the globa...

  • EPSS 0.58%
  • Veröffentlicht 25.05.2026 10:41:16
  • Zuletzt bearbeitet 23.07.2026 17:10:00

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate...

  • EPSS 0.95%
  • Veröffentlicht 08.01.2025 09:15:07
  • Zuletzt bearbeitet 03.06.2025 21:11:55

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user have not been cleared, leadin...

  • EPSS 0.93%
  • Veröffentlicht 05.08.2024 08:15:56
  • Zuletzt bearbeitet 19.03.2025 15:15:49

Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user f...