Actively Exploited Vulnerabilities
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
Apply updates per vendor instructions.
CWE-1188
CWE-306