Apache AirflowGHSA-rg94-84xj-7gq3
Apache Airflow Contains Open Redirect
Medium6.1CVE-2022-45402 · Published Nov 15, 2022 · updated Apr 30, 2025
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.4.3 | 2.4.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-601
- Also known as
- BIT-airflow-2022-45402, CVE-2022-45402, PYSEC-2022-42984
- nvd.nist.gov/vuln/detail/CVE-2022-45402
- github.com/apache/airflow/pull/27576
- github.com/apache/airflow/commit/f0f67e8bc9dcb9444cfc5b88ee075191785469b7
- github.com/apache/airflow
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2022-42984.yaml
- lists.apache.org/thread/nf4xrkoo6c81g6fdn4vj8k9x2686o9nh
- www.openwall.com/lists/oss-security/2022/11/15/1
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 222022 | OS Command Injection in Apache Airflow | Critical9.8 | 2.3.0 |
| Nov 222022 | OS Command Injection in Apache Airflow | Critical9.8 | 2.3.0 |
| Nov 222022 | OS Command Injection in Apache Airflow | Medium5.5 | 2.3.0 |
| Nov 142022 | Apache Airflow vulnerable to OS Command Injection via example DAGs | High8.8 | 2.4.0 |
| Nov 142022 | Apache Airflow subject to Exposure of Sensitive Information | High7.5 | 2.3.1 |
| Nov 22022 | Apache Airflow Cross-site Scripting vulnerability | Medium6.1 | 2.4.2rc1 |