CVE-2021-45229 — Cross-site Scripting in Software Foundation Apache Airflow
Severity
6.1MEDIUMNVD
EPSS
1.6%
top 18.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 25
Latest updateFeb 26
Description
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages2 packages
🔴Vulnerability Details
4OSV▶
CVE-2021-45229: It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument↗2022-02-25