Reflected cross-site scripting (XSS) In apache-airflow
Description
Apache Airflow Cross-site Scripting vulnerability
In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the origin query argument.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
pypi | 2.4.2rc1 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.