In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's /login endpoint.
/login
{ "cpes": [ "cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*" ], "severity": "Medium" }