Vulnerabilities
Vulnerable Software
Apache:  >> Airflow  >> 1.10.13  Security Vulnerabilities
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.13. This is same as CVE-2020-13944 but the implemented fix in Airflow 1.10.13 did not fix the issue completely.
CVSS Score
6.1
EPSS Score
0.101
Published
2020-12-11
In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.
CVSS Score
6.1
EPSS Score
0.17
Published
2020-09-17


Contact Us

Shodan ® - All rights reserved