Skip to content
Apache AirflowGHSA-68wv-rjrm-576p

Cross-Site Request Forgery (CSRF) in Apache Airflow

High8.8CVE-2017-17835 · Published Jan 25, 2019 · updated Sep 11, 2024

In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.9.01.9.0
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow vulnerable to CSRF Attacks
High8.8Apr 18, 2019
Apache Airflow vulnerable to Stored XSS
Medium4.8Apr 12, 2019
Apache Airflow vulnerable to Stored XSS
Medium5.5Mar 6, 2019
Improper Certificate Validation in Apache Airflow
High7.5Jan 25, 2019
Apache Airflow vulnerable to XSS
Critical9.8Jan 25, 2019
Improper Input Validation in Apache Airflow resulting in Remote Code Execution
High8.8Jan 25, 2019

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.