Apache Apache-Airflow-Providers-Fab vulnerabilities
4 known vulnerabilities affecting apache/apache-airflow-providers-fab.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-42447P3CRITICALCVSS 9.8v1.2.1v1.2.02024-08-05
CVE-2024-42447 [CRITICAL] CWE-613 CVE-2024-42447: Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects A
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB.
This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user from logging out.
* FAB provider 1.2.1 only affected Airflow 2.9.3 (earlier and later versions of Ai
ghsanvdosv
CVE-2026-59245P3HIGHCVSS 8.1fixed in 3.7.22026-07-13
CVE-2026-59245 [HIGH] CWE-269 CVE-2026-59245: In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists an
nvd
CVE-2024-45033P3HIGHCVSS 8.1fixed in 1.5.22025-01-08
CVE-2024-45033 [HIGH] CVE-2024-45033: Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Ap
Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider.
This issue affects Apache Airflow Fab Provider: before 1.5.2.
When user password has been changed with admin CLI, the sessions for that user have not been cleared, leading to insufficient session expiration, thus logged users could continue to be logged in even after the password w
ghsanvdosv
CVE-2026-46745P3MEDIUMCVSS 5.3fixed in 3.6.42026-05-25
CVE-2026-46745 [MEDIUM] CWE-90 CVE-2026-46745: Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.
ghsanvd