Skip to content
Apache AirflowGHSA-j38c-25fj-mr84

Stored XSS in Apache Airflow

Medium6.1CVE-2020-9485 · Published Jul 27, 2020 · updated Sep 11, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.111.10.11
Details and references

An issue was found in Apache Airflow versions 1.10.10 and below. A stored XSS vulnerability was discovered in the Chart pages of the the "classic" UI.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
BIT-airflow-2020-9485, CVE-2020-9485, PYSEC-2020-23

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Jul 272020Multiple stored XSS in RBAC Admin screens in Apache Airflow
CVE-2020-11983Medium5.4fixed in 1.10.11
Jul 272020Command injection via Celery broker in Apache Airflow
CVE-2020-11981Critical9.8fixed in 1.10.11rc1
Jul 272020Insecure default config of Celery worker in Apache Airflow
CVE-2020-11982Critical9.8fixed in 1.10.11
Jul 272020Remote code execution (RCE) in Apache Airflow
CVE-2020-11978High8.8fixed in 1.10.11rc1
May 62020XSS in Apache Airflow
CVE-2019-12398Medium4.8fixed in 1.10.5
Dec 172020Apache Airflow logs passwords in plaintext
CVE-2020-17511Low2.8fixed in 1.10.13

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.