CVE-2026-59243
- EPSS 0.68%
- Veröffentlicht 29.07.2026 08:35:37
- Zuletzt bearbeitet 05.08.2026 18:37:13
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an ar...
CVE-2026-59245
- EPSS 0.36%
- Veröffentlicht 13.07.2026 15:05:21
- Zuletzt bearbeitet 14.07.2026 14:16:36
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the globa...
CVE-2026-46745
- EPSS 0.58%
- Veröffentlicht 25.05.2026 10:41:16
- Zuletzt bearbeitet 23.07.2026 17:10:00
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate...
CVE-2024-45033
- EPSS 0.95%
- Veröffentlicht 08.01.2025 09:15:07
- Zuletzt bearbeitet 03.06.2025 21:11:55
Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user have not been cleared, leadin...
CVE-2024-42447
- EPSS 0.93%
- Veröffentlicht 05.08.2024 08:15:56
- Zuletzt bearbeitet 19.03.2025 15:15:49
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user f...