Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-38054


In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.


Published

2022-09-02T07:15:07.777

Last Modified

2024-11-21T07:15:39.843

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-384
  • Type: Primary
    CWE-384

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache airflow ≤ 2.3.3 Yes

References