QID 997546
Date Published: 2024-02-28
QID 997546: Python (Pip) Security Update for apache-airflow (GHSA-rv25-9wgj-xg75)
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. However Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rv25-9wgj-xg75 for updates and patch information.
Vendor References
- GHSA-rv25-9wgj-xg75 -
github.com/advisories/GHSA-rv25-9wgj-xg75
CVEs related to QID 997546
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rv25-9wgj-xg75 | apache-airflow |
|