It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-09-16T21:57:17.157Z

Reserved: 2017-08-07T00:00:00

Link: CVE-2017-12614

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-06T13:29:00.233

Modified: 2024-11-21T03:09:53.860

Link: CVE-2017-12614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.