PT-2023-8379 · Apache · Apache Airflow

Andrey Anshin

+1

·

Publicado

2023-12-21

·

Atualizado

2024-03-06

·

CVE-2023-47265

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 2.6.0 through 2.7.3
Description The issue is related to a stored XSS vulnerability that allows a DAG author to add unbounded and not-sanitized JavaScript in the parameter description field of the DAG. This JavaScript can be executed on the client side of any user who looks at the tasks in the browser sandbox, allowing modification of what the user sees in the browser. This opens up possibilities of misleading other users.
Recommendations For Apache Airflow versions 2.6.0 through 2.7.3, upgrade to version 2.8.0 or newer to mitigate the risk associated with this vulnerability. As a temporary workaround, consider restricting access to the parameter description field of the DAG to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-00575
BIT-AIRFLOW-2023-47265
CVE-2023-47265
GHSA-PXCH-WR7M-RWXJ
PYSEC-2023-264

Produtos afetados

Apache Airflow