Skip to content
Apache AirflowGHSA-q4p3-qw5c-mhpc

Multiple stored XSS in RBAC Admin screens in Apache Airflow

Medium5.4CVE-2020-11983 · Published Jul 27, 2020 · updated Sep 11, 2024

An issue was found in Apache Airflow versions 1.10.10 and below. It was discovered that many of the admin management screens in the new/RBAC UI handled escaping incorrectly, allowing authenticated users with appropriate permissions to create stored XSS attacks.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.111.10.11
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow logs passwords in plaintext
Low2.8Dec 17, 2020
Stored XSS in Apache Airflow
Medium6.1Jul 27, 2020
Command injection via Celery broker in Apache Airflow
Critical9.8Jul 27, 2020
Insecure default config of Celery worker in Apache Airflow
Critical9.8Jul 27, 2020
Remote code execution (RCE) in Apache Airflow
High8.8Jul 27, 2020
XSS in Apache Airflow
Medium4.8May 6, 2020

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.