Loading HuntDB...

CVE-2020-17526

UNKNOWN
Published 2020-12-21T16:45:13.000Z
Actions:
No CVSS data available

Description

Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This does not affect users who have changed the default value for `[webserver] secret_key` config.

Available Exploits

Apache Airflow <1.10.14 - Authentication Bypass

Apache Airflow prior to 1.10.14 contains an authentication bypass vulnerability via incorrect session validation with default configuration. An attacker on site A can access unauthorized Airflow on site B through the site A session.

ID: CVE-2020-17526
Author: piyushchhiroliya High

Related News

No news articles found for this CVE.

Affected Products

References

Published: 2020-12-21T16:45:13.000Z
Last Modified: 2025-02-13T16:27:35.877Z
Copied to clipboard!