Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in the Apache Airflow Keycloak provider that could allow unauthorized access to your Airflow environment. If your Keycloak realm is shared with other applications, an attacker could use the credentials of any confidential client within that realm to log into Airflow, potentially gaining access to sensitive data or systems.
- Unauthorized access to Airflow via shared credentials.
- Matters for environments sharing Keycloak realms.
- Confirm relevance and exposure of Airflow Keycloak integration.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by using the valid credentials of any confidential client registered in the same Keycloak realm as Airflow, even if that client is not intended for Airflow. This allows the attacker to authenticate as that client's service account and obtain a signed session token, granting them the same access rights as that service account. The endpoint also permits unauthenticated credential guessing against Keycloak under Airflow's identity.
- Unauthenticated access to shared realm.
- Client credentials grant token issuance.
- Access as unrelated service account.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an attacker to impersonate any service account within a shared Keycloak realm by using valid credentials for an unrelated confidential client. When supported by the advisory, this could lead to unauthorized access to Airflow resources based on the permissions of the impersonated service account, and potentially allow unauthenticated credential guessing against Keycloak under Airflow's identity.
- Service account credentials.
- Valid unrelated client credentials.
- Unauthorized resource access.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts deployments of the Apache Airflow Keycloak provider when the Keycloak realm is shared with other confidential clients. The primary responsibility for addressing this likely falls to the platform or application team managing the Airflow instance, in coordination with the security or network team responsible for the Keycloak infrastructure. The first practical step is to identify all Airflow instances using the Keycloak auth manager, confirm their exposure and criticality, and then ascertain the specific Airflow and Keycloak client configurations to plan remediation.
- Platform and app teams own the issue.
- Verify shared realm and client credentials.
- Plan vendor-coordinated remediation.