Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts which client ids may authen
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow Keycloak provider | 0 ~ 0.10.0 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-84501 | Apache ZooKeeper EnsembleAuthenticationProvider 操作日志伪造漏洞 | |
| CVE-2026-84439 | Apache ZooKeeper 审计日志注入漏洞 | |
| CVE-2026-79993 | Apache ZooKeeper 容器节点删除权限缺失漏洞 | |
| CVE-2026-59969 | ZooKeeper FIPS模式下主机不匹配证书验证不当 | |
| CVE-2026-59739 | Apache ZooKeeper 重连重放信息泄露 | |
| CVE-2026-86466 | Apache Airflow FAB提供商认证令牌校验缺失 | |
| CVE-2026-76186 | Apache Airflow Keycloak令牌会话绑定缺失 | |
| CVE-2026-82310 | Airflow FAB认证失效用户保留核心API权限 | |
| CVE-2026-86792 | Apache Kafka provider 远程代码执行漏洞 | |
| CVE-2026-86462 | Apache Airflow FAB密码更新未失效会话漏洞 | |
| CVE-2026-82311 | Apache Airflow FAB 密码重置会话失效失败 | |
| CVE-2026-86465 | Airflow Akeyless Provider 作用域绕过漏洞 |
暂无评论