CVE-2020-13944

Publication date

2020-09-17 14:01:40

Family

apache

State

PUBLISHED

Description

In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like /trigger was vulnerable to XSS exploit.