Описание
Apache Airflow Potential Cross-site Scripting Vulnerability
Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2024-39863
- https://github.com/apache/airflow/pull/40475
- https://github.com/apache/airflow/commit/f18f48492dc69f392e45567580b6ddb0c070ea58
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2024-189.yaml
- https://lists.apache.org/thread/gxkvs279f1mbvckv5q65worr6how20o3
- http://www.openwall.com/lists/oss-security/2024/07/16/6
Пакеты
apache-airflow
< 2.9.3
2.9.3
EPSS
5.1 Medium
CVSS4
5.4 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue.
Apache Airflow versions before 2.9.3 have a vulnerability that allows ...
Уязвимость компонента Provider сетевого программного средства Apache Airflow, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)
EPSS
5.1 Medium
CVSS4
5.4 Medium
CVSS3