Reflected cross-site scripting (XSS) In apache-airflow
Description
Apache Airflow Cross-site Scripting Vulnerability
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the origin query argument. This issue affects Apache Airflow versions 2.2.3 and below.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
pypi | 2.2.4rc1 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.