Опубликовано: 08 мая 2023
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 5.4
Описание
Apache Airflow vulnerable to stored Cross-site Scripting
Task instance details page in the UI is vulnerable to stored cross-site scripting. This issue affects Apache Airflow before 2.6.0.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-29247
- https://github.com/apache/airflow/pull/30447
- https://github.com/apache/airflow/pull/30779
- https://github.com/apache/airflow/commit/46c85ec11d224c133da6c45c1186c9aa498a7e75
- https://github.com/apache/airflow/commit/f819dfcb24c597058b7b671f6317e4c84976975e
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-60.yaml
- https://lists.apache.org/thread/kqf5lxmko133780clsp827xfsh4xd3fl
Пакеты
Наименование
apache-airflow
pip
Затронутые версииВерсия исправления
< 2.6.0
2.6.0
Связанные уязвимости
CVSS3: 5.4
nvd
больше 2 лет назад
Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.
CVSS3: 5.4
debian
больше 2 лет назад
Task instance details page in the UI is vulnerable to a stored XSS.Thi ...