oss-sec mailing list archives

CVE-2024-41937: Apache Airflow: Stored XSS Vulnerability on provider link


From: Ephraim Anierobi <ephraimanierobi () apache org>
Date: Wed, 21 Aug 2024 14:08:00 +0000

Severity: low

Affected versions:

- Apache Airflow before 2.10.0

Description:

Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to 
execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider 
to be installed on the web server and theĀ user to click the provider link.
Users should upgrade to 2.10.0 or later, which fixes this vulnerability.

Credit:

sw0rd1ight (https://github.com/sw0rd1ight) (finder)
Amogh Desai (remediation developer)

References:

https://github.com/apache/airflow/pull/40933
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-41937


Current thread: