Security Advisory

CVE-2018-20244

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-02-27 18:00:00
Last updated 2024-09-16 22:24:36
Assigner apache
State PUBLISHED

Description

In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.