cbcvebase.
CVE-2023-29247
published 2023-05-08

CVE-2023-29247: Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.

Affected

2 ranges
VendorProductVersion rangeFixed in
apacheairflow< 2.6.02.6.0
apache_software_foundationapache_airflow< 2.6.02.6.0