Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a flaw in Apache Airflow's API logout function. If users log out using a specific header instead of the standard session cookie, their token is not properly invalidated, potentially allowing an attacker who previously obtained the token to maintain access. The main concern is confirming relevance and exposure.
- Logout flaw lets valid tokens persist.
- Stolen tokens grant continued access.
- Confirm if your Airflow API is exposed.
Attack Path
How an attacker could exploit the issue
An attacker who has already obtained a victim's valid session token can maintain access even after the victim logs out, as the logout function fails to invalidate tokens presented via the Authorization header. This allows the attacker to continue using the session until the token naturally expires, which is typically 24 hours but can be configured.
- Requires a pre-existing valid token.
- Logout endpoint incorrectly handles bearer tokens.
- Persistent unauthorized access to victim's account.
Live Threat
Current exploitation, exposure, and threat context
When users log out of Apache Airflow using a bearer token, the session may remain active if the token is presented in the Authorization header instead of a cookie. An attacker who has already obtained a copy of this token could maintain unauthorized access to the victim's account until the token expires, which by default is 24 hours.
- API session tokens.
- Logout via Authorization header.
- Continued unauthorized access.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts Apache Airflow deployments where API clients authenticate using bearer tokens. The primary responsibility for addressing this likely falls to the platform or infrastructure teams managing Airflow, in coordination with application owners who utilize its API. The first practical step is to identify all Airflow instances, confirm their network reachability and business criticality, and then determine the accountable owner for remediation planning.
- Platform/Infrastructure teams own resolution.
- Verify Airflow API bearer token usage.
- Plan remediation based on exposure risk.