Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q4p3-qw5c-mhpc

Опубликовано: 27 июл. 2020
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 5.4

Описание

Multiple stored XSS in RBAC Admin screens in Apache Airflow

An issue was found in Apache Airflow versions 1.10.10 and below. It was discovered that many of the admin management screens in the new/RBAC UI handled escaping incorrectly, allowing authenticated users with appropriate permissions to create stored XSS attacks.

Пакеты

Наименование

apache-airflow

pip
Затронутые версииВерсия исправления

< 1.10.11

1.10.11

EPSS

Процентиль: 61%
0.00411
Низкий

5.1 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

An issue was found in Apache Airflow versions 1.10.10 and below. It was discovered that many of the admin management screens in the new/RBAC UI handled escaping incorrectly, allowing authenticated users with appropriate permissions to create stored XSS attacks.

CVSS3: 5.4
debian
больше 5 лет назад

An issue was found in Apache Airflow versions 1.10.10 and below. It wa ...

EPSS

Процентиль: 61%
0.00411
Низкий

5.1 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79