oss-sec mailing list archives

Re: [CVE-2020-13944] Apache Airflow Reflected XSS via Origin Parameter <= 1.10.12


From: Kaxil Naik <kaxilnaik () gmail com>
Date: Wed, 16 Sep 2020 15:09:39 +0100

Correction the issue only affects < 1.10.12 (not <= 1.10.12)

On Wed, Sep 16, 2020, 12:27 Kaxil Naik <kaxilnaik () gmail com> wrote:

Versions Affected: <= 1.10.12
Description:
The "origin" parameter passed to some of the endpoints like '/trigger' was
vulnerable to XSS exploit.

Credit:
The issue was independently discovered and reported by Ali Al-Habsi of
Accellion & Everardo Padilla Saca.

Thanks,
Kaxil,
on behalf of Apache Airflow PMC


Current thread: