CVE-2022-43982: Apache Airflow prior to 2.4.2 allows reflected XSS via Origin Query Argument in URL
In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the origin query argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/apache-airflowto a version that resolves this vulnerability.Fixed in 2.4.2rc1 - Upgrade
Upgrade
Apache Airflowto a version that resolves this vulnerability.Fixed in 2.4.2
Event History
Frequently Asked Questions
What is CVE-2022-43982?
CVE-2022-43982 is a vulnerability in Apache Airflow versions prior to 2.4.2 that allows XSS attacks via the 'origin' query argument.
How severe is CVE-2022-43982?
CVE-2022-43982 has a severity rating of medium with a CVSS score of 6.1.
How does CVE-2022-43982 affect Apache Airflow?
CVE-2022-43982 affects Apache Airflow versions prior to 2.4.2.
How can I fix CVE-2022-43982?
To fix CVE-2022-43982, you should upgrade Apache Airflow to version 2.4.2 or newer.
Where can I find more information about CVE-2022-43982?
You can find more information about CVE-2022-43982 on the GitHub pull request (https://github.com/apache/airflow/pull/27143) and Apache mailing list (https://lists.apache.org/thread/vqnvdrfsw9z7v7c46qh3psjgr7wy959l).