CVE-2022-38054Session Fixation in Software Foundation Apache Airflow

CWE-384Session Fixation5 documents4 sources
Severity
9.8CRITICALNVD
EPSS
2.2%
top 15.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 2
Latest updateSep 3

Description

In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5apache_software_foundation/apache_airflow2.2.4Apache Airflow*
NVDapache/airflow2.2.42.3.3

🔴Vulnerability Details

4
GHSA
Apache Airflow Session Fixation vulnerability2022-09-03
OSV
Apache Airflow Session Fixation vulnerability2022-09-03
OSV
CVE-2022-38054: In Apache Airflow versions 22022-09-02
CVEList
Session Fixation2022-09-02
CVE-2022-38054 — Session Fixation | cvebase