Horizon Alert
Summary of the vulnerability and why it matters
This advisory describes a vulnerability in Apache Airflow where a user's authentication token could be reused if intercepted after logout, potentially allowing unauthorized access. While a fix is available, the primary concern is to confirm if your environment uses the affected versions and if the logout functionality and token interception are relevant scenarios for your operations.
- Logged-out tokens can be reused.
- Critical vulnerability in session token handling.
- Confirm Airflow usage and exposure.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this by intercepting a valid user's session token after they log out. This token, if not invalidated by the system, can be reused by the attacker to gain unauthorized access to the user's account and potentially perform actions as that user.
- Token can be intercepted after logout.
- Reused token grants unauthorized access.
- Risk of account takeover and data compromise.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an attacker to reuse a previously intercepted JWT token after a user logs out, potentially granting them unauthorized access to the affected system. This could occur if a token is intercepted while a user is still authenticated or during the logout process before the token is invalidated.
- User session tokens at risk.
- Token reuse after logout.
- Unauthorized system access.
Operational Fix
Recommended remediation, mitigation, and detection steps
Platform or application owners are responsible for addressing this vulnerability, as it affects the session token invalidation mechanism in Apache Airflow. The first practical step is to identify all Airflow instances, determine their reachability and criticality, confirm ownership, and then plan remediation based on these findings.
- Confirm Airflow instance ownership and exposure.
- Verify affected Airflow instances and their criticality.
- Plan remediation, likely involving upgrades.