In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's /login endpoint.
/login
{ "severity": "Medium", "cpes": [ "cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*" ] }