Insufficient Session Expiration in Apache Airflow Fab Provider
CVE-2024-45033
8.1HIGH
What is CVE-2024-45033?
An insufficient session expiration vulnerability exists in the Apache Airflow Fab Provider, which allows users to remain logged in even after their password has been modified through the admin CLI. This issue was specifically noted in versions prior to 1.5.2, and it poses a risk since users might retain session access despite a password change. In contrast, session handling behaves securely when password changes are initiated via the web server. For enhanced security, it is recommended that users upgrade to version 1.5.2, which addresses this oversight.
Affected Version(s)
Apache Airflow Fab Provider 0 < 1.5.2