Skip to content
Apache AirflowPYSEC-2019-216

A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.

Medium4.8CVE-2019-12417 · Published Oct 30, 2019 · updated Jul 6, 2026

Source advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.6rc11.10.6rc1

Changes since it was listed

DateChange
Sep 24Severity: Unrated to Medium
Details and references

A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Severity from
NVD
Also known as
CVE-2019-12417, GHSA-q3p4-gw7r-wqjc, PYSEC-2026-617

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
May 62020XSS in Apache Airflow
CVE-2019-12398Medium4.8fixed in 1.10.5
Apr 182019Apache Airflow vulnerable to CSRF Attacks
CVE-2019-0229High8.8fixed in 1.10.3
Apr 122019Apache Airflow vulnerable to Stored XSS
CVE-2019-0216Medium4.8fixed in 1.10.3
Mar 62019Apache Airflow vulnerable to Stored XSS
CVE-2018-20244Medium5.5fixed in 1.10.2
Jul 272020Multiple stored XSS in RBAC Admin screens in Apache Airflow
CVE-2020-11983Medium5.4fixed in 1.10.11
Jul 272020Command injection via Celery broker in Apache Airflow
CVE-2020-11981Critical9.8fixed in 1.10.11rc1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.