CISA description
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
Apache · Airflow's Experimental API
Apache Airflow's Experimental API Authentication Bypass
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
Apply updates per vendor instructions.
Vulnerability data triggers these controls during assessment and continuous monitoring.