Skip to content
Apache AirflowGHSA-9gqg-3fxr-9hv7

Apache Airflow vulnerable to XSS

Critical9.8CVE-2017-17836 · Published Jan 25, 2019 · updated Sep 12, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.9.01.9.0
Details and references

In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow, weather it be via XSS or by leaving a machine unlocked can exfil all credentials from the system.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
CVE-2017-17836, PYSEC-2019-149

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Jan 252019Improper Input Validation in Apache Airflow resulting in Remote Code Execution
CVE-2017-15720High8.8fixed in 1.9.0
Jan 252019Cross-Site Request Forgery (CSRF) in Apache Airflow
CVE-2017-17835High8.8fixed in 1.9.0
Jan 252019Improper Certificate Validation in Apache Airflow
CVE-2018-20245High7.5fixed in 1.10.1
Mar 62019Apache Airflow vulnerable to Stored XSS
CVE-2018-20244Medium5.5fixed in 1.10.2
Apr 122019Apache Airflow vulnerable to Stored XSS
CVE-2019-0216Medium4.8fixed in 1.10.3
Apr 182019Apache Airflow vulnerable to CSRF Attacks
CVE-2019-0229High8.8fixed in 1.10.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.