Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2020-13944
In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.17
EPSS Ranking
94.7%
CVSS Severity
CVSS v3 Score
6.1
CVSS v2 Score
4.3
References
http://www.openwall.com/lists/oss-security/2020/12/11/2
http://www.openwall.com/lists/oss-security/2021/05/01/2
https://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cannounce.apache.org%3E
https://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cdev.airflow.apache.org%3E
https://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cusers.airflow.apache.org%3E
https://lists.apache.org/thread.html/r4656959c8ed06c1f6202d89aa4e67b35ad7bdba5a666caff3fea888e%40%3Cusers.airflow.apache.org%3E
https://lists.apache.org/thread.html/r97e1b60ca508a86be58c43f405c0c8ff00ba467ba0bee68704ae7e3e%40%3Cdev.airflow.apache.org%3E
https://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3E
https://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3E
http://www.openwall.com/lists/oss-security/2020/12/11/2
http://www.openwall.com/lists/oss-security/2021/05/01/2
https://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cannounce.apache.org%3E
https://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cdev.airflow.apache.org%3E
https://lists.apache.org/thread.html/r2892ef594dbbf54d0939b808626f52f7c2d1584f8aa1d81570847d2a%40%3Cusers.airflow.apache.org%3E
https://lists.apache.org/thread.html/r4656959c8ed06c1f6202d89aa4e67b35ad7bdba5a666caff3fea888e%40%3Cusers.airflow.apache.org%3E
https://lists.apache.org/thread.html/r97e1b60ca508a86be58c43f405c0c8ff00ba467ba0bee68704ae7e3e%40%3Cdev.airflow.apache.org%3E
https://lists.apache.org/thread.html/ra8ce70088ba291f358e077cafdb14d174b7a1ce9a9d86d1b332d6367%40%3Cusers.airflow.apache.org%3E
https://lists.apache.org/thread.html/rc005f4de9d9b0ba943ceb8ff5a21a5c6ff8a9df52632476698d99432%40%3Cannounce.apache.org%3E
Products affected by CVE-2020-13944
Apache
»
Airflow
»
Version:
N/A
cpe:2.3:a:apache:airflow:-
Apache
»
Airflow
»
Version:
0.1
cpe:2.3:a:apache:airflow:0.1
Apache
»
Airflow
»
Version:
0.2
cpe:2.3:a:apache:airflow:0.2
Apache
»
Airflow
»
Version:
0.2.1
cpe:2.3:a:apache:airflow:0.2.1
Apache
»
Airflow
»
Version:
0.2.2
cpe:2.3:a:apache:airflow:0.2.2
Apache
»
Airflow
»
Version:
0.2.3
cpe:2.3:a:apache:airflow:0.2.3
Apache
»
Airflow
»
Version:
0.3
cpe:2.3:a:apache:airflow:0.3
Apache
»
Airflow
»
Version:
0.3.1
cpe:2.3:a:apache:airflow:0.3.1
Apache
»
Airflow
»
Version:
0.3.2
cpe:2.3:a:apache:airflow:0.3.2
Apache
»
Airflow
»
Version:
0.4
cpe:2.3:a:apache:airflow:0.4
Apache
»
Airflow
»
Version:
0.4.1
cpe:2.3:a:apache:airflow:0.4.1
Apache
»
Airflow
»
Version:
0.4.2
cpe:2.3:a:apache:airflow:0.4.2
Apache
»
Airflow
»
Version:
0.4.3
cpe:2.3:a:apache:airflow:0.4.3
Apache
»
Airflow
»
Version:
0.4.5
cpe:2.3:a:apache:airflow:0.4.5
Apache
»
Airflow
»
Version:
0.4.6
cpe:2.3:a:apache:airflow:0.4.6
Apache
»
Airflow
»
Version:
0.5.0
cpe:2.3:a:apache:airflow:0.5.0
Apache
»
Airflow
»
Version:
1.0.0
cpe:2.3:a:apache:airflow:1.0.0
Apache
»
Airflow
»
Version:
1.0.1
cpe:2.3:a:apache:airflow:1.0.1
Apache
»
Airflow
»
Version:
1.1.0
cpe:2.3:a:apache:airflow:1.1.0
Apache
»
Airflow
»
Version:
1.1.1
cpe:2.3:a:apache:airflow:1.1.1
Apache
»
Airflow
»
Version:
1.10.0
cpe:2.3:a:apache:airflow:1.10.0
Apache
»
Airflow
»
Version:
1.10.1
cpe:2.3:a:apache:airflow:1.10.1
Apache
»
Airflow
»
Version:
1.10.10
cpe:2.3:a:apache:airflow:1.10.10
Apache
»
Airflow
»
Version:
1.10.11
cpe:2.3:a:apache:airflow:1.10.11
Apache
»
Airflow
»
Version:
1.10.12
cpe:2.3:a:apache:airflow:1.10.12
Apache
»
Airflow
»
Version:
1.10.13
cpe:2.3:a:apache:airflow:1.10.13
Apache
»
Airflow
»
Version:
1.10.14
cpe:2.3:a:apache:airflow:1.10.14
Apache
»
Airflow
»
Version:
1.10.2
cpe:2.3:a:apache:airflow:1.10.2
Apache
»
Airflow
»
Version:
1.10.5
cpe:2.3:a:apache:airflow:1.10.5
Apache
»
Airflow
»
Version:
1.10.6
cpe:2.3:a:apache:airflow:1.10.6
Apache
»
Airflow
»
Version:
1.10.7
cpe:2.3:a:apache:airflow:1.10.7
Apache
»
Airflow
»
Version:
1.10.8
cpe:2.3:a:apache:airflow:1.10.8
Apache
»
Airflow
»
Version:
1.10.9
cpe:2.3:a:apache:airflow:1.10.9
Apache
»
Airflow
»
Version:
1.2.0
cpe:2.3:a:apache:airflow:1.2.0
Apache
»
Airflow
»
Version:
1.3.0
cpe:2.3:a:apache:airflow:1.3.0
Apache
»
Airflow
»
Version:
1.4.0
cpe:2.3:a:apache:airflow:1.4.0
Apache
»
Airflow
»
Version:
1.4.1
cpe:2.3:a:apache:airflow:1.4.1
Apache
»
Airflow
»
Version:
1.5.0
cpe:2.3:a:apache:airflow:1.5.0
Apache
»
Airflow
»
Version:
1.5.1
cpe:2.3:a:apache:airflow:1.5.1
Apache
»
Airflow
»
Version:
1.5.2
cpe:2.3:a:apache:airflow:1.5.2
Apache
»
Airflow
»
Version:
1.6.0
cpe:2.3:a:apache:airflow:1.6.0
Apache
»
Airflow
»
Version:
1.6.1
cpe:2.3:a:apache:airflow:1.6.1
Apache
»
Airflow
»
Version:
1.6.2
cpe:2.3:a:apache:airflow:1.6.2
Apache
»
Airflow
»
Version:
1.7.0
cpe:2.3:a:apache:airflow:1.7.0
Apache
»
Airflow
»
Version:
1.7.1
cpe:2.3:a:apache:airflow:1.7.1
Apache
»
Airflow
»
Version:
1.7.1.1
cpe:2.3:a:apache:airflow:1.7.1.1
Apache
»
Airflow
»
Version:
1.7.1.2
cpe:2.3:a:apache:airflow:1.7.1.2
Apache
»
Airflow
»
Version:
1.7.1.3
cpe:2.3:a:apache:airflow:1.7.1.3
Apache
»
Airflow
»
Version:
1.8.0
cpe:2.3:a:apache:airflow:1.8.0
Apache
»
Airflow
»
Version:
1.8.1
cpe:2.3:a:apache:airflow:1.8.1
Apache
»
Airflow
»
Version:
1.8.2
cpe:2.3:a:apache:airflow:1.8.2
Apache
»
Airflow
»
Version:
1.9.0
cpe:2.3:a:apache:airflow:1.9.0
Apache
»
Airflow
»
Version:
2.0.0
cpe:2.3:a:apache:airflow:2.0.0
Apache
»
Airflow
»
Version:
2.0.1
cpe:2.3:a:apache:airflow:2.0.1
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved