
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-17526 affects Apache Airflow Webserver versions prior to 1.10.14. The vulnerability involves incorrect session validation in the default configuration that allows a malicious Airflow user on site A, where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This vulnerability does not affect users who have modified the default value for [webserver] secret_key configuration (NVD Database, OpenWall List).
The vulnerability has been assigned a CVSS v3.1 Base Score of 7.7 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N. The vulnerability stems from improper session validation in the default configuration of the Airflow Webserver, specifically related to the [webserver] secret_key configuration parameter (NVD Database).
The vulnerability allows unauthorized access across different Airflow Webserver instances. An attacker who has legitimate access to one Airflow instance (Site A) can leverage their session to gain unauthorized access to another Airflow Webserver instance (Site B), potentially exposing sensitive information (OpenWall List).
The vulnerability requires the attacker to have legitimate access to at least one Airflow instance. The attack can be executed remotely with low attack complexity and requires low privileges. No user interaction is needed for exploitation (NVD Database).
The primary mitigation is to change the default value for the [webserver] secret_key configuration parameter. Users who have already modified this default value are not affected by this vulnerability (OpenWall List).
The vulnerability was discovered and reported by Junghan Lee of Deliveryhero Korea Security Team. The Apache Airflow team addressed this security issue in version 1.10.14 (OpenWall List).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."