Skip to content
Apache AirflowGHSA-8p7v-2jvj-v54r

Apache Airflow vulnerable to Stored XSS

Medium4.8CVE-2019-0216 · Published Apr 12, 2019 · updated Sep 11, 2024

A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.31.10.3
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow vulnerable to CSRF Attacks
High8.8Apr 18, 2019
Apache Airflow vulnerable to Stored XSS
Medium5.5Mar 6, 2019
Improper Certificate Validation in Apache Airflow
High7.5Jan 25, 2019
Cross-Site Request Forgery (CSRF) in Apache Airflow
High8.8Jan 25, 2019
Apache Airflow vulnerable to XSS
Critical9.8Jan 25, 2019
Improper Input Validation in Apache Airflow resulting in Remote Code Execution
High8.8Jan 25, 2019

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.