CVE-2020-13944
published 2020-09-17CVE-2020-13944: In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.
PriorityP338medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
25.08%
97.7th percentile
In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 1.10.15 | 1.10.15 |
| apache | airflow | >= 1.0.0 < 1.10.15 | 1.10.15 |
| apache | airflow | >= 2.0.0 < 2.0.2 | 2.0.2 |
| apache_software_foundation | apache_airflow | — | — |
| apache_software_foundation | apache_airflow | — | — |
| apache_software_foundation | apache_airflow | >= Apache Airflow < 1.10.15 | 1.10.15 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Airflow Cross-site Scripting
osv·2021-06-18
CVE-2020-13944 [MEDIUM] Apache Airflow Cross-site Scripting
Apache Airflow Cross-site Scripting
In Apache Airflow < 1.10.12, the `origin` parameter passed to some of the endpoints like `/trigger` and was vulnerable to a XSS exploit.
GHSA
Cross-site Scripting in Apache Airflow
ghsa·2021-06-18·CVSS 6.1
CVE-2021-28359 [MEDIUM] CWE-79 Cross-site Scripting in Apache Airflow
Cross-site Scripting in Apache Airflow
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions <1.10.15 in 1.x series and affects 2.0.0 and 2.0.1 and 2.x series. This is the same as CVE-2020-13944 & CVE-2020-17515 but the implemented fix did not fix the issue completely. Update to Airflow 1.10.15 or 2.0.2. Please also update your Python version to the latest available PATCH releases of the installed MINOR versions, example update to Python 3.6.13 if you are on Python 3.6. (Those contain the fix for CVE-2021-23336 https://nvd.nist.gov/vuln/detail/CVE-2021-23336).
OSV
Cross-site Scripting in Apache Airflow
osv·2021-06-18·CVSS 6.1
CVE-2021-28359 [MEDIUM] Cross-site Scripting in Apache Airflow
Cross-site Scripting in Apache Airflow
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions <1.10.15 in 1.x series and affects 2.0.0 and 2.0.1 and 2.x series. This is the same as CVE-2020-13944 & CVE-2020-17515 but the implemented fix did not fix the issue completely. Update to Airflow 1.10.15 or 2.0.2. Please also update your Python version to the latest available PATCH releases of the installed MINOR versions, example update to Python 3.6.13 if you are on Python 3.6. (Those contain the fix for CVE-2021-23336 https://nvd.nist.gov/vuln/detail/CVE-2021-23336).
GHSA
Apache Airflow Cross-site Scripting
ghsa·2021-06-18
CVE-2020-13944 [MEDIUM] CWE-79 Apache Airflow Cross-site Scripting
Apache Airflow Cross-site Scripting
In Apache Airflow < 1.10.12, the `origin` parameter passed to some of the endpoints like `/trigger` and was vulnerable to a XSS exploit.
OSV
CVE-2021-28359: The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit
osv·2021-05-02·CVSS 6.1
CVE-2021-28359 [MEDIUM] CVE-2021-28359: The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions <1.10.15 in 1.x series and affects 2.0.0 and 2.0.1 and 2.x series. This is the same as CVE-2020-13944 & CVE-2020-17515 but the implemented fix did not fix the issue completely. Update to Airflow 1.10.15 or 2.0.2. Please also update your Python version to the latest available PATCH releases of the installed MINOR versions, example update to Python 3.6.13 if you are on Python 3.6. (Those contain the fix for CVE-2021-23336 https://nvd.nist.gov/vuln/detail/CVE-2021-23336).
GHSA
Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
ghsa·2021-04-20·CVSS 6.1
CVE-2020-17515 [MEDIUM] CWE-79 Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
The `origin` parameter passed to some of the endpoints like `/trigger` was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.15. This is same as CVE-2020-13944 but the implemented fix in Airflow 1.10.13 did not fix the issue completely.
OSV
Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
osv·2021-04-20·CVSS 6.1
CVE-2020-17515 [MEDIUM] Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
The `origin` parameter passed to some of the endpoints like `/trigger` was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.15. This is same as CVE-2020-13944 but the implemented fix in Airflow 1.10.13 did not fix the issue completely.
OSV
CVE-2020-17515: The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit
osv·2020-12-11·CVSS 6.1
CVE-2020-17515 [MEDIUM] CVE-2020-17515: The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.13. This is same as CVE-2020-13944 but the implemented fix in Airflow 1.10.13 did not fix the issue completely.
OSV
CVE-2020-13944: In Apache Airflow < 1
osv·2020-09-17
CVE-2020-13944 CVE-2020-13944: In Apache Airflow < 1
In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2020/12/11/2http://www.openwall.com/lists/oss-security/2021/05/01/2https://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cdev.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cusers.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r4656959c8ed06c1f6202d89aa4e67b35ad7bdba5a666caff3fea888e%40%3Cusers.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r97e1b60ca508a86be58c43f405c0c8ff00ba467ba0bee68704ae7e3e%40%3Cdev.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3Ehttp://www.openwall.com/lists/oss-security/2020/12/11/2http://www.openwall.com/lists/oss-security/2021/05/01/2https://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cdev.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cusers.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r4656959c8ed06c1f6202d89aa4e67b35ad7bdba5a666caff3fea888e%40%3Cusers.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/r97e1b60ca508a86be58c43f405c0c8ff00ba467ba0bee68704ae7e3e%40%3Cdev.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3Ehttps://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3E
2020-09-17
Published