Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-vcf6-3wv2-5vcr: Apache Airflow vulnerable to stored Cross-site Scripting

Task instance details page in the UI is vulnerable to stored cross-site scripting. This issue affects Apache Airflow before 2.6.0.

ghsa
#xss#apache#git

Apache Airflow vulnerable to stored Cross-site Scripting

Moderate severity GitHub Reviewed Published May 8, 2023 to the GitHub Advisory Database • Updated May 8, 2023

Related news

CVE-2023-29247: Improve url detection for task instance details by pierrejeambrun · Pull Request #30779 · apache/airflow

Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.