CVE List

CVE-2022-41672

Critical 8.1

In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.

Published October 7, 2022.

Affected software

Get alerts for Apache Airflow

Reference links