CVE-2018-20244
published 2019-02-27CVE-2018-20244: In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on…
PriorityP429medium5.5CVSS 3.0
AVNACLPRHUINSCCLILAN
EPSS
1.96%
77.9th percentile
In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 1.10.2 | 1.10.2 |
| apache_software_foundation | apache_airflow | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Airflow vulnerable to Stored XSS
ghsa·2019-03-06
CVE-2018-20244 [MEDIUM] CWE-79 Apache Airflow vulnerable to Stored XSS
Apache Airflow vulnerable to Stored XSS
In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
OSV
Apache Airflow vulnerable to Stored XSS
osv·2019-03-06
CVE-2018-20244 [MEDIUM] Apache Airflow vulnerable to Stored XSS
Apache Airflow vulnerable to Stored XSS
In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
OSV
CVE-2018-20244: In Apache Airflow before 1
osv·2019-02-27
CVE-2018-20244 CVE-2018-20244: In Apache Airflow before 1
In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2019/04/10/6https://lists.apache.org/thread.html/2de387213d45bc626d27554a1bde7b8c67d08720901f82a50b6f4231%40%3Cdev.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/f656fddf9c49293b3ec450437c46709eb01a12d1645136b2f1b8573b%40%3Cdev.airflow.apache.org%3Ehttp://www.openwall.com/lists/oss-security/2019/04/10/6https://lists.apache.org/thread.html/2de387213d45bc626d27554a1bde7b8c67d08720901f82a50b6f4231%40%3Cdev.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/f656fddf9c49293b3ec450437c46709eb01a12d1645136b2f1b8573b%40%3Cdev.airflow.apache.org%3E
2019-02-27
Published