In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's /confirm endpoint.
/confirm
"https://github.com/pypa/advisory-database/blob/main/vulns/apache-airflow/PYSEC-2022-42971.yaml"