CVE-2019-0216: XSS
Published Apr 10, 2019
·Updated
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
Affected Software
2 affected componentsFixes available
Apache Airflow<=1.10.2
pip/apache-airflow<1.10.3
1.10.3
Event History
Apr 10, 2019
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionWeakness
Apr 12, 2019
Advisory Published
08:42 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-0216?
CVE-2019-0216 is considered a high severity vulnerability due to its potential for executing arbitrary JavaScript by malicious admin users.
2
How do I fix CVE-2019-0216?
To mitigate CVE-2019-0216, upgrade Apache Airflow to version 1.10.4 or later.
3
What versions of Apache Airflow are affected by CVE-2019-0216?
CVE-2019-0216 affects Apache Airflow versions up to 1.10.3.
4
Who can exploit CVE-2019-0216?
CVE-2019-0216 can be exploited by malicious admin users with access to the Airflow metadata database.
5
What kind of attacks can occur due to CVE-2019-0216?
CVE-2019-0216 can lead to cross-site scripting (XSS) attacks on certain page views in Apache Airflow.