PT-2024-29645 · Apache · Apache Airflow

Amogh Desai

+1

·

Published

2024-08-21

·

Updated

2024-09-07

·

CVE-2024-41937

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.10.0
Description The issue allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This requires the provider to be installed on the web server and the user to click the provider link.
Recommendations For Apache Airflow versions prior to 2.10.0, upgrade to 2.10.0 or later, which fixes this issue. As a temporary workaround, consider restricting access to provider documentation links to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2024-41937
CVE-2024-41937
GHSA-W7CP-G8V7-R54M
PYSEC-2024-181

Affected Products

Apache Airflow