« Volver al listado

Apache

Apache-airflow-providers-fab: vulnerabilidades y CVE

Apache-airflow-providers-fab tiene 10 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses8
Críticas5
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-86466Alta (8.1)0.37%—16 sept 2026
Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity…
CVE-2026-82310Alta (7.2)1.0%—16 sept 2026
Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to…
CVE-2026-86462Crítica (9.1)0.83%—16 sept 2026
Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's…
CVE-2026-82311Crítica (9.8)0.98%—16 sept 2026
Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login…
CVE-2026-75156Crítica (9.1)0.38%—8 sept 2026
Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with…
CVE-2026-59243Crítica (9.8)0.64%—29 jul 2026
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass…
CVE-2026-59245Alta (8.1)0.60%—13 jul 2026
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG…
CVE-2026-46745Media (5.3)0.76%—25 may 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to…
CVE-2024-45033Alta (8.1)0.95%—8 ene 2025
Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user…
CVE-2024-42447Crítica (9.8)0.93%—5 ago 2024
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1210 Exploitation of Remote Services3
  3. T1078 Valid Accounts2
  4. T1078.001 Default Accounts2
  5. T1068 Exploitation for Privilege Escalation1
  6. T1078.004 Cloud Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Apache