Описание
Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user to click the provider link. Users should upgrade to 2.10.0 or later, which fixes this vulnerability.
Уязвимые конфигурации
Конфигурация 1Версия до 2.10.0 (исключая)
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00651
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
debian
больше 1 года назад
Apache Airflow, versions before 2.10.0, have a vulnerability that allo ...
CVSS3: 6.1
github
больше 1 года назад
Apache Airflow Cross-site Scripting Vulnerability
EPSS
Процентиль: 70%
0.00651
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79