Apache Airflow: XSS vulnerability in Task Instance Log/Log Details
Moderate severity
GitHub Reviewed
Published
May 14, 2024
to the GitHub Advisory Database
•
Updated Feb 13, 2025
Description
Published by the National Vulnerability Database
May 14, 2024
Published to the GitHub Advisory Database
May 14, 2024
Reviewed
May 14, 2024
Last updated
Feb 13, 2025
Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.
Users are recommended to upgrade to version 2.9.1, which fixes this issue.
References