apache-airflow-providers-fab is vulnerable to Authentication Bypass
98
Critical Risk
The FAB auth manager's Azure AD OAuth login decodes the incoming id_token with signature verification turned off by default. Because verify_signature defaults to a value that skips validation, a forged or unsigned (alg:none) token presented to the OAuth callback is accepted as authentic. Anyone able to reach that callback can log in as an arbitrary user, including an account holding the Admin role. The fix flips the default so the Azure AD id_token signature is verified, matching the Authentik login path.
You are affected if you are using a version that falls within the vulnerable range and you run the FAB auth manager with the Azure AD OAuth login path enabled. In that configuration signature verification is skipped by default, so an untrusted id_token submitted to the OAuth callback is accepted without validation. Deployments that do not enable the Azure AD OAuth login path are not exposed.
apache-airflow-providers-fab is vulnerable to Authentication Bypass in versions 0.0.1 - 3.7.2.
Upgrade the apache-airflow-providers-fab library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant