Apache

Apache-airflow-providers-keycloak

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 16.09.2026 09:10:57
  • Zuletzt bearbeitet 18.09.2026 14:27:16

Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts which client ids ...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 09:09:57
  • Zuletzt bearbeitet 18.09.2026 14:26:45

Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthent...

Medienbericht
  • EPSS 0.33%
  • Veröffentlicht 18.04.2026 13:22:41
  • Zuletzt bearbeitet 11.05.2026 15:09:48

The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm co...