CVE-2019-0216
published 2019-04-10CVE-2019-0216: A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
PriorityP423medium4.8CVSS 3.0
AVNACLPRHUIRSCCLILAN
EPSS
2.77%
84.6th percentile
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | <= 1.10.2 | — |
CVSS provenance
nvdv3.04.8MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Airflow vulnerable to Stored XSS
ghsa·2019-04-12
CVE-2019-0216 [MEDIUM] CWE-79 Apache Airflow vulnerable to Stored XSS
Apache Airflow vulnerable to Stored XSS
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
OSV
Apache Airflow vulnerable to Stored XSS
osv·2019-04-12
CVE-2019-0216 [MEDIUM] Apache Airflow vulnerable to Stored XSS
Apache Airflow vulnerable to Stored XSS
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
OSV
CVE-2019-0216: A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views
osv·2019-04-10
CVE-2019-0216 CVE-2019-0216: A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2019/04/10/6http://www.securityfocus.com/bid/107869https://lists.apache.org/thread.html/2de387213d45bc626d27554a1bde7b8c67d08720901f82a50b6f4231%40%3Cdev.airflow.apache.org%3Ehttp://www.openwall.com/lists/oss-security/2019/04/10/6http://www.securityfocus.com/bid/107869https://lists.apache.org/thread.html/2de387213d45bc626d27554a1bde7b8c67d08720901f82a50b6f4231%40%3Cdev.airflow.apache.org%3E
2019-04-10
Published