Headline
GHSA-vcf6-3wv2-5vcr: Apache Airflow vulnerable to stored Cross-site Scripting
Task instance details page in the UI is vulnerable to stored cross-site scripting. This issue affects Apache Airflow before 2.6.0.
Apache Airflow vulnerable to stored Cross-site Scripting
Moderate severity GitHub Reviewed Published May 8, 2023 to the GitHub Advisory Database • Updated May 8, 2023
Related news
CVE-2023-29247: Improve url detection for task instance details by pierrejeambrun · Pull Request #30779 · apache/airflow
Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.