CVE-2021-45229Cross-site Scripting in Software Foundation Apache Airflow

Severity
6.1MEDIUMNVD
EPSS
1.6%
top 18.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateFeb 26

Description

It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5apache_software_foundation/apache_airflowunspecified2.2.4
NVDapache/airflow2.2.3

🔴Vulnerability Details

4
OSV
Apache Airflow Cross-site Scripting Vulnerability2022-02-26
GHSA
Apache Airflow Cross-site Scripting Vulnerability2022-02-26
CVEList
Apache Airflow: Reflected XSS via Origin Query Argument in URL2022-02-25
OSV
CVE-2021-45229: It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument2022-02-25
CVE-2021-45229 — Cross-site Scripting | cvebase