CVE-2022-41672: Session still functional after user is deactivated
In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/apache-airflowto a version that resolves this vulnerability.Fixed in 2.4.1rc1
Event History
Frequently Asked Questions
What is the vulnerability ID for this Apache Airflow vulnerability?
The vulnerability ID for this Apache Airflow vulnerability is CVE-2022-41672.
What is the severity of CVE-2022-41672?
The severity of CVE-2022-41672 is high with a CVSS score of 8.1.
How does CVE-2022-41672 impact Apache Airflow?
CVE-2022-41672 allows an already authenticated user to continue using the UI or API even after their account has been deactivated.
How can I fix CVE-2022-41672?
To fix CVE-2022-41672, users should update to Apache Airflow version 2.4.1 or later.
Where can I find more information about CVE-2022-41672?
More information about CVE-2022-41672 can be found at the following references: [Reference 1](https://github.com/apache/airflow/pull/26635), [Reference 2](https://lists.apache.org/thread/ohf3pvd3dftb8zb01yngbn1jtkq5m08y).