CVE-2020-13927: Apache Airflow's Experimental API Authentication Bypass
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication. Required action: Apply updates per vendor instructions.
CISA KEV ↗ · unattributed attribution