Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a vulnerability in the Apache Airflow Keycloak authentication provider, specifically impacting deployments using version 3.3 or later. The issue allows an attacker to potentially gain unauthorized privileges by pairing a valid session with a mismatched authentication token, impacting system integrity and access controls. The main concern is confirming relevance and exposure.
- Mismatched tokens allow unauthorized access.
- Affects Airflow 3.3+ with Keycloak.
- Confirm if your Airflow deployment is impacted.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by first gaining their own valid Airflow login. Then, they would need to obtain a Keycloak access or refresh token belonging to another user through an out-of-band method. By pairing their existing Airflow session with this foreign token, the attacker can then make requests authenticated with the privileges of the other user, impacting the integrity and confidentiality of the system.
- Attacker has own Airflow login.
- Pairs foreign token with Airflow session.
- Unauthorized actions with another user's privileges.
Live Threat
Current exploitation, exposure, and threat context
When the Apache Airflow Keycloak provider is running with specific configurations, an attacker could impersonate another user by combining their own valid Airflow session with a foreign Keycloak token. This could allow them to perform actions or access data as the other user, as the system would authorize requests using the foreign token's privileges while logging them under the attacker's account.
- Unauthorized access to user data or system functions.
- Foreign tokens obtained out-of-band.
- Impersonation and unauthorized actions.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts Apache Airflow deployments using the Keycloak authentication manager with versions 3.3 and later. The primary responsibility for addressing this issue likely falls to the Platform or Infrastructure Team managing Airflow, in coordination with Security Teams for exposure assessment and Vendor Management if the Keycloak integration is managed by a third party. The first practical move is to identify all Airflow instances utilizing the Keycloak provider, confirm their network reachability, and ascertain their business criticality to prioritize remediation efforts.
- Platform/Infrastructure team owns remediation.
- Verify Keycloak auth manager reachability.
- Plan upgrade to version 0.10.0.