PT-2022-12314 · Apache · Apache Airflow

Ali Al-Habsi

+1

·

Published

2022-02-25

·

Updated

2024-03-06

·

CVE-2021-45229

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 2.2.3 and below
Description The "Trigger DAG with config" screen in Apache Airflow is susceptible to XSS attacks via the origin query argument.
Recommendations For Apache Airflow versions 2.2.3 and below, consider disabling the "Trigger DAG with config" screen until a patch is available to prevent XSS attacks via the origin query argument.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2021-45229
CVE-2021-45229
GHSA-65XW-PCQW-HJRH
PYSEC-2022-29

Affected Products

Apache Airflow