Date: Thu, 24 Feb 2022 18:00:13 +0000 From: Jedidiah Cunningham <jedcunningham@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2021-45229: Apache Airflow: Reflected XSS via Origin Query Argument in URL Severity: high Description: It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below. Credit: The Apache Airflow PMC would like to thank both Bogdan Kurinnoy of the Samsung R&D Institute Ukraine (SRK) and Ali Al-Habsi of Accellion for independently discovering and reporting this issue.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.