CVE-2023-47265Cross-site Scripting in Software Foundation Apache Airflow

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 58.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21

Description

Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of the user who looks at the tasks in the browser sandbox. While this issue does not allow to exit the browser sandbox or manipulation of the server-side data - more than the DAG author already has, it allows to modify what the user looking at t

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDapache/airflow2.6.02.7.3

Patches

🔴Vulnerability Details

4
OSV
Apache Airflow has a stored cross-site scripting vulnerability2023-12-21
OSV
CVE-2023-47265: Apache Airflow, versions 22023-12-21
GHSA
Apache Airflow has a stored cross-site scripting vulnerability2023-12-21
CVEList
Apache Airflow: DAG Params alllow to embed unchecked Javascript2023-12-21
CVE-2023-47265 — Cross-site Scripting | cvebase