The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade apache-airflow-providers-keycloak to version 0.10.0rc1 or higher.
apache-airflow-providers-keycloak is a Provider package apache-airflow-providers-keycloak for Apache Airflow
Affected versions of this package are vulnerable to Reliance on Cookies without Validation and Integrity Checking via get_user_from_token in keycloak_auth_manager.py, where Keycloak access and refresh tokens carried in separate _access_token and _refresh_token cookies are attached to a session without verifying that they belong to the same subject as the signed Airflow JWT. An attacker can pair their own valid Airflow session with another user's Keycloak token, causing every authorization decision to be made using the victim's Keycloak privileges while the session identity, audit records, and logs continue to reflect the attacker's own identity.