Skip to content
Apache AirflowGHSA-pm87-24wq-r8w9

Apache Airflow Session Fixation vulnerability

High8.0CVE-2023-40273 · Published Aug 23, 2023 · updated Sep 11, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.7.0rc22.7.0rc2
Details and references

The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user. Other than manually cleaning the session database (for database session backend), or changing the secure_key and restarting the webserver, there were no mechanisms to force-logout the user (and all other users with that). With this fix implemented, when using the database session backend, the existing sessions of the user are invalidated when the password of the user is reset. When using the securecookie session backend, the sessions are NOT invalidated and still require changing the secure key and restarting the webserver (and logging out all other users), but the user resetting the password is informed about it with a flash message warning displayed in the UI. Documentation is also updated explaining this behaviour. Users of Apache Airflow are advised to upgrade to version 2.7.0 or newer to mitigate the risk associated with this vulnerability.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-384
Also known as
BIT-airflow-2023-40273, CVE-2023-40273, PYSEC-2023-158

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Aug 232023Apache Airflow missing Certificate Validation
CVE-2023-39441Medium5.9fixed in 2.7.0
Aug 232023Apache Airflow denial of service vulnerability
CVE-2023-37379High8.1fixed in 2.7.0b1
Aug 112023Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.
CVE-2023-39553High7.5fixed in 2.4.3
Aug 52023Apache Airflow Execution with Unnecessary Privileges
CVE-2023-39508High8.8fixed in 2.6.0b1
Sep 122023Apache Airflow Incorrect Authorization vulnerability
CVE-2023-40611Medium4.3fixed in 2.7.1
Sep 122023Apache Airflow information exposure vulnerability
CVE-2023-40712High6.5fixed in 2.7.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.