PT-2020-15029 · Apache · Apache Airflow

Kaxil Naik

·

Published

2020-12-14

·

Updated

2024-03-06

·

CVE-2020-17513

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 1.10.13
Description The Charts and Query View of the old (Flask-admin based) UI in Apache Airflow were vulnerable to a Server-Side Request Forgery (SSRF) attack.
Recommendations For versions prior to 1.10.13, update to version 1.10.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the Charts and Query View of the old UI to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2020-17513
CVE-2020-17513
GHSA-6R3P-FCVM-XH7C
PYSEC-2020-20

Affected Products

Apache Airflow