Skip to content
luigiGHSA-p69g-f978-xxv9

Cross-Site Request Forgery (CSRF) in Luigi

High8.8CVE-2018-1000843 · Published Dec 20, 2018 · updated Sep 30, 2024

Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contains a Cross ite Request Forgery (CSRF) vulnerability in API endpoint: /api/<method> that can result in Task metadata such as task name, id, parameter, etc. will be leaked to unauthorized users. This attack appear to be exploitable via The victim must visit a specially crafted webpage from the network where their Luigi server is accessible.. This vulnerability appears to have been fixed in 2.8.0 and later.

GitHub advisory

Affected versions

PackageAffectedFixed in
luigi
PyPI
< 2.8.02.8.0
Details and references

More luigi advisories

All luigi
Advisory
luigi Arbitrary File Write via Archive Extraction (Zip Slip)
High8.6Dec 10, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.