Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65xw-pcqw-hjrh

Опубликовано: 26 фев. 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Apache Airflow Cross-site Scripting Vulnerability

It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the origin query argument. This issue affects Apache Airflow versions 2.2.3 and below.

Пакеты

Наименование

apache-airflow

pip
Затронутые версииВерсия исправления

< 2.2.4rc1

2.2.4rc1

EPSS

Процентиль: 81%
0.01563
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.

CVSS3: 6.1
debian
почти 4 года назад

It was discovered that the "Trigger DAG with config" screen was suscep ...

EPSS

Процентиль: 81%
0.01563
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79