Skip to content
Apache AirflowGHSA-f9fq-78ch-4wmj

Apache Airflow Open Redirect vulnerability

Medium6.1CVE-2022-43985 · Published Nov 2, 2022 · updated May 2, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.4.2rc12.4.2rc1
Details and references

In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-601
Also known as
BIT-airflow-2022-43985, CVE-2022-43985, PYSEC-2022-42971

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Nov 22022Apache Airflow Cross-site Scripting vulnerability
CVE-2022-43982Medium6.1fixed in 2.4.2rc1
Nov 142022Apache Airflow vulnerable to OS Command Injection via example DAGs
CVE-2022-40127High8.8fixed in 2.4.0
Nov 142022Apache Airflow subject to Exposure of Sensitive Information
CVE-2022-27949High7.5fixed in 2.3.1
Nov 152022Apache Airflow Contains Open Redirect
CVE-2022-45402Medium6.1fixed in 2.4.3
Nov 222022OS Command Injection in Apache Airflow
CVE-2022-40954Medium5.5fixed in 2.3.0
Nov 222022OS Command Injection in Apache Airflow
CVE-2022-38649Critical9.8fixed in 2.3.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.