PT-2020-15029 · Apache · Apache Airflow

·

CVE-2020-17513

·

Published

2020-12-14

·

Updated

2024-03-06

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 1.10.13
Description The Charts and Query View of the old (Flask-admin based) UI in Apache Airflow were vulnerable to a Server-Side Request Forgery (SSRF) attack.
Recommendations For versions prior to 1.10.13, update to version 1.10.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the Charts and Query View of the old UI to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2020-17513
CVE-2020-17513
GHSA-6R3P-FCVM-XH7C
PYSEC-2020-20

Affected Products

Apache Airflow