Severity: medium 

Affected versions:

- Apache Airflow Providers Amazon (apache-airflow-providers-amazon) 8.0.0 
before 9.22.0

Description:

In AWS Auth manager, the origin of the SAML authentication has been used as 
provided by the client and not verified against the actual instance URL. 
This allowed to gain access to different instances with potentially different 
access controls by reusing SAML response from other instances.

You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.

Credit:

Sungwuk Jung (finder)

References:

https://github.com/apache/airflow/pull/61368
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-25604

Reply via email to