CVE-2020-17513Server-Side Request Forgery in Software Foundation Apache Airflow

Severity
5.3MEDIUMNVD
EPSS
2.1%
top 15.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 14
Latest updateDec 17

Description

In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDapache/airflow< 1.10.13
CVEListV5apache_software_foundation/apache_airflowApache Airflow1.10.13

🔴Vulnerability Details

4
GHSA
SSRF vulnerability in Apache Airflow2020-12-17
OSV
SSRF vulnerability in Apache Airflow2020-12-17
OSV
CVE-2020-17513: In Apache Airflow versions prior to 12020-12-14
CVEList
CVE-2020-17513: In Apache Airflow versions prior to 12020-12-14