Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a vulnerability in the Apache Airflow FAB provider where resetting a user's password does not correctly invalidate their existing sessions. This means an attacker holding a compromised session cookie can maintain access even after the password has been changed, potentially bypassing security containment actions.
- Password resets may not end active user sessions.
- Compromised sessions remain active post-reset.
- Confirm exposure and ensure timely upgrades.
Attack Path
How an attacker could exploit the issue
An attacker can maintain access to a victim's account even after their password has been reset, provided the attacker already possesses a copy of the victim's session cookie. This occurs because the system fails to properly invalidate existing database-backed sessions when a password reset is initiated. The vulnerability is present when the FAB auth manager is configured to use a database for session storage. This allows an attacker to retain unauthorized access to a user's account, bypassing the intended security measure of a password reset.
- Victim's session cookie must be compromised.
- Password reset command is executed.
- Attacker keeps unauthorized access.
Live Threat
Current exploitation, exposure, and threat context
When the FAB auth manager uses a database-backed session, resetting a user's password does not invalidate their existing session cookies. This means an attacker who has already stolen a user's session cookie can maintain access to that user's account even after the password has been changed.
- Existing user sessions are at risk.
- Stolen session cookies enable continued access.
- Unwanted access persists after password reset.
Operational Fix
Recommended remediation, mitigation, and detection steps
For deployments using the FAB auth manager with `[fab] session_backend=database`, the platform or application owner is responsible for addressing this vulnerability. The initial step is to identify all instances of the affected Airflow FAB provider, confirm their accessibility and business criticality, and then coordinate remediation with the vendor based on the assessed risk.
- Platform/application owners should investigate.
- Verify session backend configuration and reachability.
- Plan upgrade during the next maintenance window.