CVE-2019-0216Cross-site Scripting in Apache Airflow

Severity
4.8MEDIUMNVD
EPSS
0.7%
top 28.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateApr 12

Description

A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

NVDapache/airflow1.10.2
CVEListV5apache_software_foundation/apache_airflowApache Airflow <= 1.10.2

🔴Vulnerability Details

4
GHSA
Apache Airflow vulnerable to Stored XSS2019-04-12
OSV
Apache Airflow vulnerable to Stored XSS2019-04-12
CVEList
CVE-2019-0216: A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views2019-04-10
OSV
CVE-2019-0216: A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views2019-04-10
CVE-2019-0216 — Cross-site Scripting in Apache Airflow | cvebase