Apache Airflow AWS Auth Manager
cpe:2.3:a:apache:apache-airflow-providers-amazon:*:*:*:*:*:*:*
- >= 8.0.0, < 9.22.0
A vulnerability in the AWS Auth manager of Apache Airflow Providers Amazon versions 8.0.0 prior to 9.22.0 allows for SAML authentication bypass. The issue arises because the origin of the SAML authentication is accepted as provided by the client without verification against the actual instance URL. This flaw enables access to different instances with potentially varying access controls by reusing SAML responses from other instances.
Exploitation of this vulnerability could lead to unauthorized access to instances with different access controls, allowing users to bypass SAML authentication restrictions.
Users are advised to upgrade to version 9.22.0 of the Apache Airflow Providers Amazon package.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.