CyberRota Analysis
AI-GeneratedThe FAB auth manager in Apache is vulnerable due to a misconfiguration that allows an attacker to bypass authentication by presenting a forged or unsigned ID token, potentially gaining access as any user, including those with Admin privileges. This critical vulnerability affects deployments using the Azure AD OAuth login with default settings, specifically in versions prior to 3.7.3 of `apache-airflow-providers-fab`. Organizations utilizing this configuration should prioritize upgrading to version 3.7.3 or later to mitigate the risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.
Related CVEs
Other vulnerabilities affecting the same vendor(s)