Apache AirflowPYSEC-2019-216
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.
Medium4.8CVE-2019-12417 · Published Oct 30, 2019 · updated Jul 6, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 1.10.6rc1 | 1.10.6rc1 |
Changes since it was listed
| Date | Change |
|---|---|
| Sep 24 | Severity: Unrated to Medium |
Details and references
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- Severity from
- NVD
- Also known as
- CVE-2019-12417, GHSA-q3p4-gw7r-wqjc, PYSEC-2026-617
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 62020 | XSS in Apache Airflow CVE-2019-12398Medium4.8fixed in 1.10.5 | Medium4.8 | 1.10.5 |
| Apr 182019 | Apache Airflow vulnerable to CSRF Attacks CVE-2019-0229High8.8fixed in 1.10.3 | High8.8 | 1.10.3 |
| Apr 122019 | Apache Airflow vulnerable to Stored XSS CVE-2019-0216Medium4.8fixed in 1.10.3 | Medium4.8 | 1.10.3 |
| Mar 62019 | Apache Airflow vulnerable to Stored XSS CVE-2018-20244Medium5.5fixed in 1.10.2 | Medium5.5 | 1.10.2 |
| Jul 272020 | Multiple stored XSS in RBAC Admin screens in Apache Airflow CVE-2020-11983Medium5.4fixed in 1.10.11 | Medium5.4 | 1.10.11 |
| Jul 272020 | Command injection via Celery broker in Apache Airflow CVE-2020-11981Critical9.8fixed in 1.10.11rc1 | Critical9.8 | 1.10.11rc1 |