UNKNOWNKNOWN EXPLOITED
CVE-2020-13927
Apache Airflow's Experimental API Authentication Bypass
Summary
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
References
Includes data from the CISA Known Exploited Vulnerabilities catalog.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.