Skip to content
Apache AirflowGHSA-vcf6-3wv2-5vcr

Apache Airflow vulnerable to stored Cross-site Scripting

Medium5.4CVE-2023-29247 · Published May 8, 2023 · updated Sep 12, 2024

Task instance details page in the UI is vulnerable to stored cross-site scripting. This issue affects Apache Airflow before 2.6.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.6.02.6.0
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow Path Traversal vulnerability
High6.5Jul 12, 2023
Apache Airflow information disclosure vulnerability
High6.5Jul 12, 2023
Apache Airflow vulnerable to exposure of sensitive information
High6.5Jun 19, 2023
Apache Airflow vulnerable to Privilege Context Switching Error
Critical9.8May 8, 2023
Apache Airflow: improper input validation
High7.5Apr 7, 2023
Sensitive Information in Error Messages in Apache Airflow
Medium5.3Mar 15, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.