Количество 3
Количество 3
CVE-2024-41937
Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user to click the provider link. Users should upgrade to 2.10.0 or later, which fixes this vulnerability.
CVE-2024-41937
Apache Airflow, versions before 2.10.0, have a vulnerability that allo ...
GHSA-w7cp-g8v7-r54m
Apache Airflow Cross-site Scripting Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-41937 Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user to click the provider link. Users should upgrade to 2.10.0 or later, which fixes this vulnerability. | CVSS3: 6.1 | 1% Низкий | больше 1 года назад | |
CVE-2024-41937 Apache Airflow, versions before 2.10.0, have a vulnerability that allo ... | CVSS3: 6.1 | 1% Низкий | больше 1 года назад | |
GHSA-w7cp-g8v7-r54m Apache Airflow Cross-site Scripting Vulnerability | CVSS3: 6.1 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу