Skip to content
Apache AirflowGHSA-7mx5-x372-xh87

Incorrect Session Validation in Apache Airflow

High7.7CVE-2020-17526 · Published Apr 20, 2021 · updated Sep 11, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.141.10.14
Details and references

Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This does not affect users who have changed the default value for `[webserver] secret_key` config.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-269
Also known as
BIT-airflow-2020-17526, CVE-2020-17526, PYSEC-2020-22

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Apr 202021Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
CVE-2020-17515Medium6.1fixed in 1.10.15rc1, 2.0.2rc1
Apr 302021Authentication bypass in Apache Airflow
CVE-2020-13927Critical9.8fixed in 1.10.11
Apr 72021Improper Access Control in Apache Airflow
CVE-2021-26559High6.5fixed in 2.0.1rc1
Jun 182021Apache Airflow Cross-site Scripting
CVE-2020-13944Medium6.1fixed in 1.10.12
Jun 182021Improper Authentication in Apache Airflow
CVE-2021-26697Medium5.3fixed in 2.0.1rc1
Jun 182021Cross-site Scripting in Apache Airflow
CVE-2021-28359Medium6.1fixed in 1.10.15, 2.0.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.