PT-2022-26017 · Apache · Apache Airflow

Axel Chong

+1

·

Published

2022-10-07

·

Updated

2026-02-20

·

CVE-2022-41672

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.4.1
Description The issue allows an already authenticated user to continue using the UI or API even after their account has been deactivated.
Recommendations For versions prior to 2.4.1, update to version 2.4.1 or later to resolve the issue.

Fix

Insufficient Session Expiration

Improper Authorization

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2022-41672
CVE-2022-41672
GHSA-3Q8R-F3PJ-3GC4
PYSEC-2022-42983

Affected Products

Apache Airflow