PT-2020-20695 · Apache · Apache Airflow

Mika Kulmala

·

Published

2020-07-16

·

Updated

2024-03-06

·

CVE-2020-9485

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 1.10.10 and below
Description A stored XSS issue was discovered in the Chart pages of the "classic" UI.
Recommendations For Apache Airflow versions 1.10.10 and below, update to a version above 1.10.10 to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2020-9485
CVE-2020-9485
GHSA-J38C-25FJ-MR84
PYSEC-2020-23

Affected Products

Apache Airflow