CVE-2018-20244Cross-site Scripting in Apache Airflow

Severity
5.5MEDIUMNVD
EPSS
0.8%
top 25.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27
Latest updateMar 6

Description

In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDapache/airflow< 1.10.2
CVEListV5apache_software_foundation/apache_airflowApache Airflow <= 1.10.1

🔴Vulnerability Details

4
GHSA
Apache Airflow vulnerable to Stored XSS2019-03-06
OSV
Apache Airflow vulnerable to Stored XSS2019-03-06
OSV
CVE-2018-20244: In Apache Airflow before 12019-02-27
CVEList
CVE-2018-20244: In Apache Airflow before 12019-02-27
CVE-2018-20244 — Cross-site Scripting in Apache Airflow | cvebase