Session Takeover Bug in AWS Apache Airflow Reveals Larger Cloud Risk
ID: d4959821-113f-5386-a867-ce8d11ef8c5d
STIX ID: report--d4959821-113f-5386-a867-ce8d11ef8c5d
Feed Name: Dark Reading
- A vulnerability in AWS Managed Workflows for Apache Airflow (MWAA) stems from improper cookie scoping across shared parent domains, enabling "cookie tossing" that can allow session hijacking, potential remote code execution, and lateral pivoting within cloud environments. AWS has patched MWAA and, along with Microsoft, made structural changes (adding domains to the Public Suffix List or restructuring domains); Google Cloud has not implemented the fix. The report emphasizes the widespread impact on cloud-hosted web apps, the role of the Public Suffix List as a mitigation, and advises customers and AppSec engineers to verify domain PSL entries and secure same-site requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
