Database/Control plane, storage & DevOps
Apache Airflow: Core API logout does not revoke bearer tokens, so a stolen token outlives the session
Impact
The Core API logout endpoint revokes only a session token presented in the _token cookie. A client that authenticates with an Authorization bearer header gets the normal logout response while nothing is revoked, and the token stays valid until it expires - 24 hours by default, configurable. An attacker who already holds a copy of a user's token keeps that user's access after the victim has logged out and believes the session is over, which removes logout as an incident-response lever on a scheduler that orchestrates training and data pipelines. The attacker gains no privileges beyond the victim's own, and how the token was obtained is outside this issue.
Who can reach it
Network access to the Airflow Core API, holding a previously captured valid bearer token. Affects API clients that authenticate with bearer tokens rather than the browser session cookie.
What to do
Upgrade apache-airflow to 3.3.2 or later and restart the API server/webserver - a control-plane service restart, no worker or GPU node disruption. Until then, shorten the configured token lifetime and rotate the signing key if you need to invalidate outstanding tokens, since logout will not do it.
References
Related entries
- AMD EPYC / Ryzen - Hardware Validated Boot enforcement: Hardware Validated Boot is not properly enforced, so anCVE-2018-8930 · AMD EPYC / Ryzen - Hardware Validated Boot enforcementCritical
- AMD EPYC Server - protected memory region access control: Insufficient access control over protected memory regions onCVE-2018-8933 · AMD EPYC Server - protected memory region access controlCritical
- PC-DDR4 / LPDDR4X DRAM - Target Row Refresh mitigation: Non-uniform Rowhammer patterns triggered bit flips on every oneCVE-2021-42114 · PC-DDR4 / LPDDR4X DRAM - Target Row Refresh mitigationCritical
- Digi RealPort protocol (Digi console/terminal servers): RealPort is the protocol Digi console servers use to exposeCVE-2023-4299 · Digi RealPort protocol (Digi console/terminal servers)Critical
- Ivanti Connect Secure: Stack-based buffer overflowCVE-2025-0282 · Ivanti Connect SecureCritical
- Ivanti Connect Secure/ZTA: Stack-based buffer overflowCVE-2025-22457 · Ivanti Connect Secure/ZTACritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.