CVE-2022-45402: Apache Airflow: Open redirect during login
Published Nov 15, 2022
·Updated
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's /login endpoint.
Affected Software
2 affected componentsFixes available
Apache Airflow<2.4.3
pip/apache-airflow<2.4.3
2.4.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/apache-airflowto a version that resolves this vulnerability.Fixed in 2.4.3 - Upgrade
Upgrade
Apache Airflowto a version that resolves this vulnerability.Fixed in 2.4.3
Event History
Nov 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·12:00 PM
Frequently Asked Questions
1
What is CVE-2022-45402?
CVE-2022-45402 is a vulnerability in Apache Airflow versions prior to 2.4.3 that allows for an open redirect in the webserver's /login endpoint.
2
How severe is CVE-2022-45402?
CVE-2022-45402 has a severity rating of 6.1 out of 10, which is considered medium.
3
How can I fix CVE-2022-45402?
To fix CVE-2022-45402, update Apache Airflow to version 2.4.3 or later.
4
What is the CWE category for CVE-2022-45402?
CVE-2022-45402 is categorized under CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')).