CVE-2018-20244

MEDIUM

Apache Airflow < 1.10.2 - Stored Cross-Site Scripting via Metadata Database State Manipulation

Title source: llm
STIX 2.1

Description

In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.

Scores

CVSS v3 5.5
EPSS 0.0085
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
apache/airflow < 1.10.2
pypi/apache-airflow 0 - 1.10.2PyPI
Published Feb 27, 2019
Tracked Since Feb 18, 2026