← Back to browse · API

CVE-2022-45402

Severity
MEDIUM
CVSS
6.1
EPSS
0.81836
Risk score
53.04
CISA KEV
No
PoC
No
Published
2022-11-15
Modified
2025-04-30
First seen
2026-08-07
Aliases
EUVD-2022-0019, GHSA-RG94-84XJ-7GQ3, PYSEC-2022-42984
Products
Apache Software Foundation:Apache Airflow unspecified <2.4.3
Sources
euvd EUVD-2022-0019

Description

In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.

References