cbcvebase.
CVE-2021-45229
published 2022-02-25

CVE-2021-45229: It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.

Affected

2 ranges
VendorProductVersion rangeFixed in
apacheairflow<= 2.2.3
apache_software_foundationapache_airflow>= unspecified < 2.2.42.2.4