In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://github.com/apache/airflow/pull/26409 | patch third party advisory |
https://lists.apache.org/thread/cn098dcp5x3c402xrb06p3l7nz5goffm | vendor advisory mailing list |