Description
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0021 | It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above. |
Github GHSA |
GHSA-rv25-9wgj-xg75 | Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T21:57:17.157Z
Reserved: 2017-08-07T00:00:00.000Z
Link: CVE-2017-12614
No data.
Status : Modified
Published: 2018-08-06T13:29:00.233
Modified: 2024-11-21T03:09:53.860
Link: CVE-2017-12614
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA