Apache Airflow versions 3.0.0 before 3.3.2 are affected when API clients authenticate using an Authorization bearer token. Browser-style sessions that present the token through the _token cookie are not the affected logout path.
The attacker must already possess a valid copy of the victim's bearer token. The issue does not provide a way to obtain a token or grant privileges beyond those of the token's owner.
The logout endpoint returns its normal response but does not revoke a bearer token supplied in the Authorization header. A copied token can therefore remain valid until it expires; the default lifetime is 24 hours, though it is configurable.
Upgrade to Apache Airflow 3.3.2 or later. If an immediate upgrade is not possible, treat logout as insufficient to invalidate potentially exposed bearer tokens and account for the configured token expiration period.