Record summary

EIP currently links 1 Nuclei template to CVE-2020-17526.

Description

Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This does not affect users who have changed the default value for `[webserver] secret_key` config.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListApache Airflow to < 1.10.14affected
GitHub AdvisoryBefore 1.10.14 · Fixed in 1.10.14affected

Nuclei templates

1
ProjectDiscoveryHIGHApache Airflow <1.10.14 - Authentication BypassCVSS 7.7

Apache Airflow prior to 1.10.14 contains an authentication bypass vulnerability via incorrect session validation with default configuration. An attacker on site A can access unauthorized Airflow on site B through the site A session.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information or unauthorized execution of arbitrary code.

Remediation

Change default value for [webserver] secret_key config.

WeaknessesCWE-287
Authorspiyushchhiroliya
Template tagscvecve2020apacheairflowauth-bypassvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CPE: cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
Shodan: http.title:"airflow - dags" || http.html:"apache airflow"
Shodan: http.title:"sign in - airflow"
Shodan: product:"redis"
FOFA: Apache Airflow
FOFA: apache airflow
FOFA: title="airflow - dags" || http.html:"apache airflow"
FOFA: title="sign in - airflow"
Google: intitle:"sign in - airflow"
Google: intitle:"airflow - dags" || http.html:"apache airflow"

Source: ProjectDiscovery

References

Showing 12 of 15