cbcvebase.
CVE-2022-43985
published 2022-11-02

CVE-2022-43985: In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.

Affected

2 ranges
VendorProductVersion rangeFixed in
apacheairflow< 2.4.22.4.2
apache_software_foundationapache_airflow>= unspecified < 2.4.22.4.2