Skip to content
Apache AirflowGHSA-w6j4-3gh2-9f5j

Apache Airflow vulnerable to CSRF Attacks

High8.8CVE-2019-0229 · Published Apr 18, 2019 · updated Sep 12, 2024

A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site request forgery attacks.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.31.10.3
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow vulnerable to Stored XSS
Medium4.8Apr 12, 2019
Apache Airflow vulnerable to Stored XSS
Medium5.5Mar 6, 2019
Improper Certificate Validation in Apache Airflow
High7.5Jan 25, 2019
Cross-Site Request Forgery (CSRF) in Apache Airflow
High8.8Jan 25, 2019
Apache Airflow vulnerable to XSS
Critical9.8Jan 25, 2019
Improper Input Validation in Apache Airflow resulting in Remote Code Execution
High8.8Jan 25, 2019

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.