CVE-2017-12614
published 2018-08-06CVE-2017-12614: It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the…
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
2.00%
78.5th percentile
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 1.9.0 | 1.9.0 |
| apache_software_foundation | apache_airflow | < 1.9.0 | 1.9.0 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint
ghsa·2022-05-14
CVE-2017-12614 [MEDIUM] CWE-79 Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint
Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. However Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.
OSV
Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint
osv·2022-05-14
CVE-2017-12614 [MEDIUM] Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint
Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. However Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.
OSV
CVE-2017-12614: It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack
osv·2018-08-06
CVE-2017-12614 CVE-2017-12614: It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-08-06
Published