Skip to content
Apache AirflowGHSA-rjvg-q57v-mjjc

XSS in Apache Airflow

Medium4.8CVE-2019-12398 · Published May 6, 2020 · updated Sep 3, 2024

In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new "RBAC" UI is unaffected.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.51.10.5
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Stored XSS in Apache Airflow
Medium6.1Jul 27, 2020
Remote code execution (RCE) in Apache Airflow
High8.8Jul 27, 2020
Insecure default config of Celery worker in Apache Airflow
Critical9.8Jul 27, 2020
Command injection via Celery broker in Apache Airflow
Critical9.8Jul 27, 2020
Multiple stored XSS in RBAC Admin screens in Apache Airflow
Medium5.4Jul 27, 2020
A malicious admin user
Medium4.8Oct 30, 2019

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.