Vulnerabilities
Vulnerable Software
Apache:  >> Airflow  >> 2.3.3  Security Vulnerabilities
In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.
CVSS Score
6.1
EPSS Score
0.006
Published
2022-09-21
In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.
CVSS Score
9.8
EPSS Score
0.006
Published
2022-09-02
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.
CVSS Score
4.7
EPSS Score
0.001
Published
2022-09-02


Contact Us

Shodan ® - All rights reserved