CVE-2019-12417: XSS
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12417?
CVE-2019-12417 is a vulnerability in Apache Airflow that allows a malicious admin user to execute arbitrary JavaScript and disclose local files.
What is the severity of CVE-2019-12417?
The severity of CVE-2019-12417 is medium, with a severity value of 4.8.
How does CVE-2019-12417 affect Apache Airflow?
CVE-2019-12417 affects Apache Airflow by allowing a malicious admin user to edit the state of objects in the metadata database, execute arbitrary JavaScript, and disclose local files.
How can I fix CVE-2019-12417?
To fix CVE-2019-12417, update Apache Airflow to version 1.10.6 or higher.
Where can I find more information about CVE-2019-12417?
You can find more information about CVE-2019-12417 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-12417), [Apache Airflow Mailing List](https://lists.apache.org/thread.html/f3aa5ff9c7cdb5424b6463c9013f6cf5db83d26c66ea77130cbbe1bc@%3Cusers.airflow.apache.org%3E), and [GitHub Advisory](https://github.com/advisories/GHSA-q3p4-gw7r-wqjc).