Description
Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j482-47xf-p25c | Apache Airflow Potential Cross-site Scripting Vulnerability |
References
History
Fri, 13 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-13T17:05:03.928Z
Reserved: 2024-07-01T05:11:17.189Z
Link: CVE-2024-39863
Updated: 2024-09-13T17:05:03.928Z
Status : Modified
Published: 2024-07-17T08:15:01.933
Modified: 2024-11-21T09:28:26.660
Link: CVE-2024-39863
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA