CVE-2024-41937
MEDIUMApache Airflow < 2.10.0 - Stored Cross-Site Scripting via Provider Documentation Link
Title source: llmDescription
Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user to click the provider link. Users should upgrade to 2.10.0 or later, which fixes this vulnerability.
References (3)
Core 3
Core References
Patch patch
https://github.com/apache/airflow/pull/40933
Third Party Advisory vendor-advisory
https://lists.apache.org/thread/lwlmgg6hqfmkpvw5py4w53hxyl37jl6d
Scores
CVSS v3
6.1
EPSS
0.0085
EPSS Percentile
75.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
apache/airflow
< 2.10.0
pypi/apache-airflow
0 - 2.10.0PyPI
Published
Aug 21, 2024
Tracked Since
Feb 18, 2026