logo

AWS Patches Critical 'FlowFixation' Bug in Airflow Service to Prevent Session Hijacking

ID: 926cfd74-3d5c-5f2f-9459-58e954c579cf

STIX ID: report--926cfd74-3d5c-5f2f-9459-58e954c579cf

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-03-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed FlowFixation, a now-patched vulnerability in AWS Managed Workflows for Apache Airflow (MWAA) that combines session fixation and a domain misconfiguration enabling XSS-based session hijacking. An attacker who took over a victim's session could read connection strings, modify configurations, trigger DAGs, potentially achieve remote code execution on underlying instances, and move laterally; AWS and Azure mitigated the issue by updating the Public Suffix List while Google Cloud deemed the issue lower priority.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.