Skip to content
Apache AirflowGHSA-65xw-pcqw-hjrh

Apache Airflow Cross-site Scripting Vulnerability

Medium6.1CVE-2021-45229 · Published Feb 26, 2022 · updated Sep 12, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.2.4rc12.2.4rc1
Details and references

It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
BIT-airflow-2021-45229, CVE-2021-45229, PYSEC-2022-29

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Feb 262022OS Command injection in Apache Airflow
CVE-2022-24288High8.8fixed in 2.2.4
Jan 282022Improper Privilege Management in apache-airflow
CVE-2021-45230Medium6.5fixed in 2.2.0
May 142022Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint
CVE-2017-12614Medium6.1fixed in 1.9.0
May 242022Missing Authentication for Critical Function in Apache Airflow
CVE-2021-38540Critical9.8fixed in 2.1.3
Aug 302021Missing Authorization in Apache Airflow
CVE-2021-35936Medium5.3fixed in 2.1.2
Sep 32022Apache Airflow Session Fixation vulnerability
CVE-2022-38054Critical9.8fixed in 2.3.4rc1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.