Apache Airflow 3.3.0 and 3.3.1 deployments whose UI is hosted on a domain shared with other applications are the most exposed. A deployment on a dedicated domain with no co-hosted applications is not reachable through the described cookie-placement methods.
The attacker must first place a valid session cookie belonging to the attacker into the victim's browser or client. Described paths include cookie tossing from a sibling subdomain, cross-site scripting in another application sharing the parent domain, or use of a shared workstation.
The core API uses the session cookie's principal and ignores the explicitly supplied bearer token. The request executes and is recorded in the audit log as the cookie-derived identity, causing principal confusion and misattributed audit records.
No. Earlier releases do not contain the code path that caches the cookie-derived user and are not vulnerable.