cbcvebase.
CVE-2018-20244
published 2019-02-27

CVE-2018-20244: In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on…

PriorityP429medium5.5CVSS 3.0
AVNACLPRHUINSCCLILAN
EPSS
1.96%
77.9th percentile
In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.

Affected

2 ranges
VendorProductVersion rangeFixed in
apacheairflow< 1.10.21.10.2
apache_software_foundationapache_airflow

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.