The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Airflow Providers Fab
APPApache< 3.7.3
Related vulnerabilities
Apache Airflow Providers FAB — nieprawidłowe wygasanie sesji (CWE-613)
Apache Airflow FAB: privilege escalation przez kolizję nazwy DAG 'DAGs'
Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airfl...
Apache Airflow FAB Auth Manager zawiera podatność LDAP filter injection (CWE-90), która pozwala nieuwierzyteln...
Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych