First published: Wed Oct 30 2019(Updated: )
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Airflow | <=1.10.5 | |
pip/airflow | <1.10.6 | 1.10.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12417 is a vulnerability in Apache Airflow that allows a malicious admin user to execute arbitrary JavaScript and disclose local files.
The severity of CVE-2019-12417 is medium, with a severity value of 4.8.
CVE-2019-12417 affects Apache Airflow by allowing a malicious admin user to edit the state of objects in the metadata database, execute arbitrary JavaScript, and disclose local files.
To fix CVE-2019-12417, update Apache Airflow to version 1.10.6 or higher.
You can find more information about CVE-2019-12417 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-12417), [Apache Airflow Mailing List](https://lists.apache.org/thread.html/f3aa5ff9c7cdb5424b6463c9013f6cf5db83d26c66ea77130cbbe1bc@%3Cusers.airflow.apache.org%3E), and [GitHub Advisory](https://github.com/advisories/GHSA-q3p4-gw7r-wqjc).