QID 982683
QID 982683: Python (pip) Security Update for apache-airflow (GHSA-86vp-x3pr-79rx)
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.14. This is same as CVE-2020-13944 but the implemented fix in Airflow 1.10.13 did not fix the issue completely.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-86vp-x3pr-79rx for updates pertaining to this vulnerability.
Vendor References
- GHSA-86vp-x3pr-79rx -
github.com/advisories/GHSA-86vp-x3pr-79rx
CVEs related to QID 982683
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-86vp-x3pr-79rx | apache-airflow |
|