Apache AirflowGHSA-9gqg-3fxr-9hv7
Apache Airflow vulnerable to XSS
Critical9.8CVE-2017-17836 · Published Jan 25, 2019 · updated Sep 12, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 1.9.0 | 1.9.0 |
Details and references
In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow, weather it be via XSS or by leaving a machine unlocked can exfil all credentials from the system.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2017-17836, PYSEC-2019-149
- nvd.nist.gov/vuln/detail/CVE-2017-17836
- github.com/advisories/GHSA-9gqg-3fxr-9hv7
- github.com/apache/airflow
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2019-149.yaml
- lists.apache.org/thread.html/ade4d54ebf614f68dc81a08891755e60ea58ba88e0209233eeea5f57@%3Cdev.airflow.apache.org%3E
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 252019 | Improper Input Validation in Apache Airflow resulting in Remote Code Execution CVE-2017-15720High8.8fixed in 1.9.0 | High8.8 | 1.9.0 |
| Jan 252019 | Cross-Site Request Forgery (CSRF) in Apache Airflow CVE-2017-17835High8.8fixed in 1.9.0 | High8.8 | 1.9.0 |
| Jan 252019 | Improper Certificate Validation in Apache Airflow CVE-2018-20245High7.5fixed in 1.10.1 | High7.5 | 1.10.1 |
| Mar 62019 | Apache Airflow vulnerable to Stored XSS CVE-2018-20244Medium5.5fixed in 1.10.2 | Medium5.5 | 1.10.2 |
| Apr 122019 | Apache Airflow vulnerable to Stored XSS CVE-2019-0216Medium4.8fixed in 1.10.3 | Medium4.8 | 1.10.3 |
| Apr 182019 | Apache Airflow vulnerable to CSRF Attacks CVE-2019-0229High8.8fixed in 1.10.3 | High8.8 | 1.10.3 |