Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This does not affect users who have changed the default value for `[webserver] secret_key` config.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:35.877Z
Reserved: 2020-08-12T00:00:00.000Z
Link: CVE-2020-17526

No data.

Status : Modified
Published: 2020-12-21T17:15:12.507
Modified: 2024-11-21T05:08:17.777
Link: CVE-2020-17526

No data.