QID 981162
QID 981162: Python (pip) Security Update for apache-airflow (GHSA-9gqg-3fxr-9hv7)
In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow, weather it be via XSS or by leaving a machine unlocked can exfil all credentials from the system.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9gqg-3fxr-9hv7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-9gqg-3fxr-9hv7 -
github.com/advisories/GHSA-9gqg-3fxr-9hv7
CVEs related to QID 981162
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9gqg-3fxr-9hv7 | apache-airflow |
|