Apache Airflow CVE-2018-20244 HTML Injection Vulnerability
BID:107188
Info
Apache Airflow CVE-2018-20244 HTML Injection Vulnerability
| Bugtraq ID: | 107188 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-20244 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2019 12:00AM |
| Updated: | Jan 23 2019 12:00AM |
| Credit: | Michael Cole of Modus Security. |
| Vulnerable: |
Apache Airflow 1.10.1 Apache Airflow 1.10 Apache Airflow 1.9 Apache Airflow 1.8.2 Apache Airflow 1.8 Apache Airflow 1.7 Apache Airflow 1.6 Apache Airflow 1.5 Apache Airflow 1.4 Apache Airflow 1.3 Apache Airflow 0.5 |
| Not Vulnerable: |
Apache Airflow 1.10.2 |
Discussion
Apache Airflow CVE-2018-20244 HTML Injection Vulnerability
Apache Airflow is prone to a HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Apache Airflow version 1.10.1 and prior are vulnerable; other versions may also be affected.
Apache Airflow is prone to a HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Apache Airflow version 1.10.1 and prior are vulnerable; other versions may also be affected.
Exploit / POC
Apache Airflow CVE-2018-20244 HTML Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Airflow CVE-2018-20244 HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Airflow CVE-2018-20244 HTML Injection Vulnerability
References:
References:
- Apache Homepage (Apache)
- CVE-2018-20244: Stored XSS in Apache Airflow 1.10.1 (Apache)