CVE-2024-42447
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/08/2024
Last modified:
19/03/2025
Description
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB.<br />
<br />
This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user from logging out. <br />
<br />
* FAB provider 1.2.1 only affected Airflow 2.9.3 (earlier and later versions of Airflow are not affected)<br />
<br />
* FAB provider 1.2.0 affected all versions of Airflow.<br />
<br />
Users who run Apache Airflow 2.9.3 are recommended to upgrade to Apache Airflow Providers FAB version 1.2.2 which fixes the issue.<br />
<br />
Users who run Any Apache Airflow version and have FAB provider 1.2.0 are recommended to upgrade to Apache Airflow Providers FAB version 1.2.2 which fixes the issue.<br />
<br />
Also upgrading Apache Airflow to latest version available is recommended.<br />
<br />
Note: Early version of Airflow reference container images of Airflow 2.9.3 and constraint files contained FAB provider 1.2.1 version, but this is fixed in updated versions of the images. <br />
<br />
Users are advised to pull the latest Airflow images or reinstall FAB provider according to the current constraints.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:apache-airflow-providers-fab:1.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:airflow:2.9.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:apache-airflow-providers-fab:1.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:airflow:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



