CVE-2022-38054: Session Fixation
Published Sep 2, 2022
·Updated
In Apache Airflow versions 2.2.4 through 2.3.3, the database webserver session backend was susceptible to session fixation.
Affected Software
2 affected componentsFixes available
Apache Airflow>=2.2.4<=2.3.3
pip/apache-airflow>=2.2.4<2.3.4rc1
2.3.4rc1
Event History
Sep 2, 2022
CVE Published
via MITRE·07:10 AM
Data Sourced
via MITRE·07:10 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Sep 3, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-38054.
2
What is the title of the vulnerability?
The title of the vulnerability is 'In Apache Airflow versions 2.2.4 through 2.3.3 the `database` webserver session backend was susceptible to session fixation.'
3
What is the severity of CVE-2022-38054?
The severity of CVE-2022-38054 is critical with a CVSS score of 9.8.
4
What is the affected software?
The affected software is Apache Airflow versions 2.2.4 through 2.3.3.
5
What is the CWE category for CVE-2022-38054?
The CWE category for CVE-2022-38054 is CWE-384.