Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability has been identified in Apache Airflow's FAB provider that affects user session management. When a user's password is changed, existing sessions are not properly invalidated, meaning an attacker who has already compromised a user's session cookie can maintain access even after the password reset. This issue impacts deployments using the FAB authentication manager with database-backed sessions and requires an upgrade to resolve, even for those who have addressed a related vulnerability.
- Passwords changed, but old access persists.
- Session access remains after password reset.
- Confirm if your Airflow is affected.
Attack Path
How an attacker could exploit the issue
An attacker with a victim's session cookie can maintain access even after the victim changes their password. This occurs because the system fails to invalidate existing sessions when a password reset is performed through the user-edit endpoint, allowing the attacker to continue impersonating the user.
- Attacker possesses victim's session cookie.
- User changes password via admin endpoint.
- Session remains active, granting continued access.
Live Threat
Current exploitation, exposure, and threat context
When a user's password is changed in Apache Airflow deployments using the FAB auth manager with database-backed sessions, existing session cookies are not invalidated. This means an attacker possessing a valid session cookie can maintain access to the user's account even after a password reset.
- User sessions remain active after password changes.
- Session cookies grant continued unauthorized access.
- Attackers may retain access to user accounts.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in Apache Airflow's FAB provider affects deployments using database-backed sessions, where changing a user's password does not invalidate existing session cookies. The first practical move is to identify all instances of the affected technology, confirm their reachability and criticality, then pinpoint the accountable owner and plan remediation.
- Platform or application owners should own the issue.
- Verify affected Airflow instances and session management.
- Coordinate upgrade during the next maintenance window.