[CVE-2019-12417] Apache Airflow stored xss and local file disclosure vulnerability <= 1.10.5

Ash Berlin-Taylor <[email protected]> Wed, 30 Oct 2019 09:06:24 +0000
Newsgroups gmane.comp.security.oss.general,gmane.comp.apache.incubator.bigtop.devel,gmane.comp.jakarta.avalon.user
Message-ID <[email protected]>
CVE-2019-12417: Stored XSS and Local File Disclosure vulnerability=20

  Versions Affected:
  <=3D 1.10.5

  Description:
    A malicious admin user could edit the state of objects in the =
Airflow metadata database to execute arbitrary javascript on certain =
page views. This also presented a Local File Disclosure vulnerability to =
any file readable by the webserver process.

  Credit:
    Thanks to Pawel.Kurylowicz (of securing.pl), and Frantisek Uhrecky =
and Marek Takac (both of citadelo.com) for all independently reporting =
this vulnerability.=20
=20
Thanks,
Ash
Apache Airflow PMC member=