Skip to main content

CVE-2020-17526

7.7
HIGHCVSS v3.1 Base Score
91.35%
HIGH RiskEPSS (100th percentile)
NVD-CWE-noinfo

Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This does not affect users who have changed the default value for `[webserver] secret_key` config.

Published: 12/21/2020
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.7HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CVSS v2 Score

3.5

AV:N/AC:M/Au:S/C:P/I:N/A:N

EPSS Score (Exploitation Probability)

91.35%HIGH Exploitation Risk
100th percentile

This vulnerability has a 91.35% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

NVD-CWE-noinfo

Related Vulnerabilities