Apache Airflow prior to 1.10.14 contains an authentication bypass vulnerability via incorrect session validation with default configuration. An attacker on site A can access unauthorized Airflow on site B through the site A session.
id: CVE-2020-17526
info:
name: Apache Airflow <1.10.14 - Authentication Bypass
author: piyushch
...