Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-38054

In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-38054
  • Apache » Airflow » Version: 2.2.4
    cpe:2.3:a:apache:airflow:2.2.4
  • Apache » Airflow » Version: 2.2.5
    cpe:2.3:a:apache:airflow:2.2.5
  • Apache » Airflow » Version: 2.3.0
    cpe:2.3:a:apache:airflow:2.3.0
  • Apache » Airflow » Version: 2.3.1
    cpe:2.3:a:apache:airflow:2.3.1
  • Apache » Airflow » Version: 2.3.3
    cpe:2.3:a:apache:airflow:2.3.3


Contact Us

Shodan ® - All rights reserved