Apache Airflow FAB Auth Manager
cpe:2.3:a:apache:airflow_providers_fab:*:*:*:*:*:*:*, +1 more
- < 3.6.4
A vulnerability allowing LDAP filter injection has been identified in the Apache Airflow FAB Auth Manager, specifically in versions prior to 3.6.4. This vulnerability (CWE-90) allows unauthenticated attackers to exfiltrate directory data or bypass authentication. The issue is reachable through the '/auth/token' endpoint.
Exploitation of this vulnerability could lead to unauthorized access or data exfiltration from the directory via LDAP.
Users are advised to upgrade to Apache Airflow FAB provider version 3.6.4 or later. If an immediate upgrade is not possible, LDAP authentication should be disabled until the provider can be updated.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.