CVE-2020-9485: XSS
Published Jul 16, 2020
·Updated
An issue was found in Apache Airflow versions 1.10.10 and below. A stored XSS vulnerability was discovered in the Chart pages of the the "classic" UI.
Affected Software
2 affected componentsFixes available
Apache Airflow<=1.10.10
pip/apache-airflow<1.10.11
1.10.11
Event History
Jul 16, 2020
CVE Published
via MITRE·11:21 PM
Data Sourced
via MITRE·11:21 PM
DescriptionWeakness
Jul 27, 2020
Advisory Published
via GitHub·04:57 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-9485.
2
What is the severity of CVE-2020-9485?
The severity of CVE-2020-9485 is medium with a severity value of 6.1.
3
Which versions of Apache Airflow are affected by CVE-2020-9485?
Apache Airflow versions 1.10.10 and below are affected by CVE-2020-9485.
4
What is the type of vulnerability associated with CVE-2020-9485?
CVE-2020-9485 is a stored XSS vulnerability.
5
Where can I find more information about CVE-2020-9485?
You can find more information about CVE-2020-9485 at the following link: https://lists.apache.org/thread.html/r7255cf0be3566f23a768e2a04b40fb09e52fcd1872695428ba9afe91%40%3Cusers.airflow.apache.org%3E