In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's /confirm endpoint.
/confirm
{ "severity": "Medium", "cpes": [ "cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*" ] }