CVE-2021-45229: Apache Airflow: Reflected XSS via Origin Query Argument in URL
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the origin query argument. This issue affects Apache Airflow versions 2.2.3 and below.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-45229?
CVE-2021-45229 is a vulnerability that allows for XSS attacks via the `origin` query argument in the "Trigger DAG with config" screen of Apache Airflow versions 2.2.3 and below.
How severe is CVE-2021-45229?
CVE-2021-45229 has a severity rating of 6.1, which is considered medium severity.
How does CVE-2021-45229 affect Apache Airflow?
CVE-2021-45229 affects Apache Airflow versions 2.2.3 and below, making them vulnerable to XSS attacks on the "Trigger DAG with config" screen.
How can I fix CVE-2021-45229?
To fix CVE-2021-45229, it is recommended to upgrade to a version of Apache Airflow that is not affected by this vulnerability.
What is the Common Vulnerabilities and Exposures (CVE) identifier for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) identifier for this vulnerability is CVE-2021-45229.