CVE-2020-17526 describes an incorrect session validation vulnerability in Apache Airflow Webserver versions prior to 1.10.14. This flaw allows an authenticated malicious user to bypass authorization and access an unauthorized Airflow Webserver on a different site, provided the default secret_key configuration has not been changed. The vulnerability carries a CVSS score of 7.7 (HIGH), indicating a high severity. It is a network-based attack with low complexity, requiring only low privileges, and can lead to high confidentiality impact without affecting integrity or availability. While not listed on the KEV catalog, exploit intelligence shows a Nuclei template for an "Authentication Bypass" with high severity. Community discussion and media coverage are present, suggesting some awareness, but there is no indication of active exploitation or Metasploit/ExploitDB entries.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.14CPE matchmatch criteria | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.