CVE-2019-12417Cross-site Scripting in Apache Airflow

Severity
4.8MEDIUMNVD
EPSS
0.7%
top 26.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 30
Latest updateNov 22

Description

A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages3 packages

PyPIapache/airflow< 1.10.6
NVDapache/airflow1.10.5
CVEListV5apache_software_foundation/apache_airflowApache Airflow up to 1.10.5

🔴Vulnerability Details

4
GHSA
Apache Airflow vulnerable to XSS and local file disclosure2019-11-22
OSV
Apache Airflow vulnerable to XSS and local file disclosure2019-11-22
OSV
CVE-2019-12417: A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views2019-10-30
CVEList
CVE-2019-12417: A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views2019-10-30
CVE-2019-12417 — Cross-site Scripting in Apache Airflow | cvebase