CVE-2020-13944: XSS
In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.
Other sources
In Apache Airflow < 1.10.12, the origin parameter passed to some of the endpoints like /trigger and was vulnerable to a XSS exploit.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is Apache Airflow CVE-2020-13944?
Apache Airflow CVE-2020-13944 is a vulnerability in Apache Airflow versions prior to 1.10.12 that allows for cross-site scripting (XSS) exploits through the 'origin' parameter in certain endpoints.
How severe is Apache Airflow CVE-2020-13944?
Apache Airflow CVE-2020-13944 has a severity score of 6.1 (Medium).
Which versions of Apache Airflow are affected by CVE-2020-13944?
Apache Airflow versions prior to 1.10.12 are affected by CVE-2020-13944, as well as versions 2.0.0 to 2.0.2.
How can I fix Apache Airflow CVE-2020-13944?
To fix Apache Airflow CVE-2020-13944, it is recommended to upgrade to version 1.10.12 or newer if using versions prior to 1.10.12, or upgrade to version 2.0.3 or newer if using versions 2.0.0 to 2.0.2.
Where can I find more information about Apache Airflow CVE-2020-13944?
More information about Apache Airflow CVE-2020-13944 can be found in the references provided: [Reference 1](http://www.openwall.com/lists/oss-security/2020/12/11/2), [Reference 2](http://www.openwall.com/lists/oss-security/2021/05/01/2), [Reference 3](https://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a@%3Cannounce.apache.org%3E).