cbcvebase.
CVE-2022-45402
published 2022-11-15

CVE-2022-45402: In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.

Affected

2 ranges
VendorProductVersion rangeFixed in
apacheairflow< 2.4.32.4.3
apache_software_foundationapache_airflow>= unspecified < 2.4.32.4.3