Apache Airflow may allow authenticated users who have been deactivated to continue using the UI or API
High severity
GitHub Reviewed
Published
Oct 7, 2022
to the GitHub Advisory Database
•
Updated Sep 11, 2024
Description
Published by the National Vulnerability Database
Oct 7, 2022
Published to the GitHub Advisory Database
Oct 7, 2022
Reviewed
Oct 7, 2022
Last updated
Sep 11, 2024
In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.
References