CVE-2020-13944Cross-site Scripting in Software Foundation Apache Airflow

Severity
6.1MEDIUMNVD
EPSS
17.2%
top 4.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 17
Latest updateJun 18

Description

In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDapache/airflow2.0.02.0.2+1
CVEListV5apache_software_foundation/apache_airflowApache Airflow1.10.15+3

🔴Vulnerability Details

6
OSV
Apache Airflow Cross-site Scripting2021-06-18
GHSA
Apache Airflow Cross-site Scripting2021-06-18
GHSA
Cross-site Scripting in Apache Airflow2021-06-18
GHSA
Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-139442021-04-20
OSV
CVE-2020-13944: In Apache Airflow < 12020-09-17
CVE-2020-13944 — Cross-site Scripting | cvebase