CVE-2019-12398

MEDIUM

Apache Airflow < 1.10.5 - Authenticated Stored Cross-Site Scripting via Metadata Database State Manipulation

Title source: llm
STIX 2.1

Description

In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new "RBAC" UI is unaffected.

References (3)

Core 3

Scores

CVSS v3 4.8
EPSS 0.0061
EPSS Percentile 70.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
apache/airflow < 1.10.5
pypi/apache-airflow 0 - 1.10.5PyPI
Published Jan 14, 2020
Tracked Since Feb 18, 2026