PT-2020-9308 · Apache · Apache Airflow

Venkat

·

Published

2020-01-14

·

Updated

2020-05-06

·

CVE-2019-12398

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 1.10.5
Description A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views when running with the classic UI. The new RBAC UI is unaffected.
Recommendations For versions prior to 1.10.5, update to version 1.10.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the classic UI until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12398
GHSA-RJVG-Q57V-MJJC
PYSEC-2020-162

Affected Products

Apache Airflow