SCA: security update for apache-airflow-providers-fab (GHSA-62qf-qm3g-fvcw)

low Tenable Self-Hosted Container Security Plugin ID 411126

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache
Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions.
The FAB provider prevented the user from logging out. * FAB provider 1.2.1 only affected Airflow 2.9.3
(earlier and later versions of Airflow are not affected) * FAB provider 1.2.0 affected all versions of
Airflow. Users who run Apache Airflow 2.9.3 are recommended to upgrade to Apache Airflow Providers FAB
version 1.2.2 which fixes the issue. Users who run Any Apache Airflow version and have FAB provider 1.2.0
are recommended to upgrade to Apache Airflow Providers FAB version 1.2.2 which fixes the issue. Also
upgrading Apache Airflow to latest version available is recommended. Note: Early version of Airflow
reference container images of Airflow 2.9.3 and constraint files contained FAB provider 1.2.1 version, but
this is fixed in updated versions of the images. Users are advised to pull the latest Airflow images or
reinstall FAB provider according to the current constraints. (CVE-2024-42447)

See Also

https://github.com/advisories/GHSA-62qf-qm3g-fvcw

Plugin Details

Severity: Low

ID: 411126

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-42447

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Low

Base Score: 2.3

Threat Score: 0.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/5/2024

Vulnerability Publication Date: 8/5/2024

Reference Information

CVE: CVE-2024-42447

cwe: CWE-613