Skip to content
Apache AirflowGHSA-99cv-8cvv-666c

Apache Airflow vulnerable to Stored XSS

Medium5.5CVE-2018-20244 · Published Mar 6, 2019 · updated Sep 10, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.21.10.2
Details and references

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Apr 122019Apache Airflow vulnerable to Stored XSS
CVE-2019-0216Medium4.8fixed in 1.10.3
Jan 252019Improper Certificate Validation in Apache Airflow
CVE-2018-20245High7.5fixed in 1.10.1
Jan 252019Cross-Site Request Forgery (CSRF) in Apache Airflow
CVE-2017-17835High8.8fixed in 1.9.0
Jan 252019Apache Airflow vulnerable to XSS
CVE-2017-17836Critical9.8fixed in 1.9.0
Jan 252019Improper Input Validation in Apache Airflow resulting in Remote Code Execution
CVE-2017-15720High8.8fixed in 1.9.0
Apr 182019Apache Airflow vulnerable to CSRF Attacks
CVE-2019-0229High8.8fixed in 1.10.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.