[CVE-2019-12417] Apache Airflow stored xss and local file disclosure vulnerability <= 1.10.5
Ash Berlin-Taylor <[email protected]> Wed, 30 Oct 2019 09:06:24 +0000
| Newsgroups | gmane.comp.security.oss.general,gmane.comp.apache.incubator.bigtop.devel,gmane.comp.jakarta.avalon.user |
|---|---|
| Message-ID | <[email protected]> |
CVE-2019-12417: Stored XSS and Local File Disclosure vulnerability=20
Versions Affected:
<=3D 1.10.5
Description:
A malicious admin user could edit the state of objects in the =
Airflow metadata database to execute arbitrary javascript on certain =
page views. This also presented a Local File Disclosure vulnerability to =
any file readable by the webserver process.
Credit:
Thanks to Pawel.Kurylowicz (of securing.pl), and Frantisek Uhrecky =
and Marek Takac (both of citadelo.com) for all independently reporting =
this vulnerability.=20
=20
Thanks,
Ash
Apache Airflow PMC member=