CVE-2019-12398
XSS in Apache Airflow
4.8
MEDIUM
CVSS 3.1
EPSS 0.56%
Description
In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new "RBAC" UI is unaffected.
How to fix CVE-2019-12398
To remediate CVE-2019-12398, upgrade the affected package to a fixed version below.
- PyPI/apache-airflow—upgrade to 1.10.5 or later
- —upgrade to 1.10.5 or later
Is CVE-2019-12398 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.10.5
- from 0, < 1.10.5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
| osv | CVSS 3.1 | MEDIUM4.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |