Apache Airflow Cross-site Scripting Vulnerability
Moderate severity
GitHub Reviewed
Published
Feb 26, 2022
to the GitHub Advisory Database
•
Updated Sep 12, 2024
Description
Published by the National Vulnerability Database
Feb 25, 2022
Published to the GitHub Advisory Database
Feb 26, 2022
Reviewed
Mar 1, 2022
Last updated
Sep 12, 2024
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the
origin
query argument. This issue affects Apache Airflow versions 2.2.3 and below.References