CVE-2022-43985: Apache Airflow prior to 2.4.2 has an open redirect
Published Nov 2, 2022
·Updated
In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's /confirm endpoint.
Affected Software
2 affected componentsFixes available
Apache Airflow<2.4.2
pip/apache-airflow<2.4.2rc1
2.4.2rc1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/apache-airflowto a version that resolves this vulnerability.Fixed in 2.4.2rc1 - Upgrade
Upgrade
Apache Airflowto a version that resolves this vulnerability.Fixed in 2.4.2
Event History
Nov 2, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·07:00 PM
Frequently Asked Questions
1
What is the vulnerability ID of this Apache Airflow vulnerability?
The vulnerability ID of this Apache Airflow vulnerability is CVE-2022-43985.
2
What is the severity of CVE-2022-43985?
The severity of CVE-2022-43985 is medium with a CVSS score of 6.1.
3
What is the affected software of CVE-2022-43985?
The affected software of CVE-2022-43985 is Apache Airflow versions prior to 2.4.2.
4
What is the CWE ID of CVE-2022-43985?
The CWE ID of CVE-2022-43985 is 601.
5
How can I fix CVE-2022-43985?
To fix CVE-2022-43985, upgrade to Apache Airflow version 2.4.2 or later.