PT-2026-96120 · Apache · Apache Airflow
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions 3.3.0 through 3.3.1
Description
An issue exists in the Airflow core API where the system incorrectly prioritizes a session cookie over an explicit
Authorization: Bearer token when both are present in a request. This causes the system to resolve the caller based on the cookie and ignore the bearer token, leading to principal confusion and misattributed audit records. Exploitation requires an attacker to place a valid session cookie into the victim's browser or client, which can occur via cookie tossing from a sibling subdomain, cross-site scripting in a separate application sharing a parent domain, or through a shared workstation. This is primarily a risk for deployments hosting the Airflow UI on a domain shared with other applications.Recommendations
Upgrade Apache Airflow versions 3.3.0 through 3.3.1 to version 3.3.2 or later.
Exploit
Fix
LPE
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow