cbcvebase.
CVE-2018-20244
published 2019-02-27

CVE-2018-20244: In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on…

medium5.5CVSS 3.0
AVNACLPRHUINSCCLILAN
In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.

Affected

2 ranges
VendorProductVersion rangeFixed in
apacheairflow< 1.10.21.10.2
apache_software_foundationapache_airflow