CVE Database
/

CVE-2022-40754

Back to search

CVE-2022-40754

Published: Sep 21, 2022

Modified: May 27, 2025

PUBLISHED

Description

In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.

VendorProductVersions

Apache Software Foundation

Apache Airflow

affected
unspecified - < 2.4.0
affected
2.3.0 - < unspecified

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now