SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-12398

In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.

MEDIUM 4.8EPSS 2.82%

Does this matter?

Lower severity and a low EPSS score (2.82%). Track it; it rarely justifies an emergency change on its own.

Description

In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new "RBAC" UI is unaffected.

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS
2.82% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
apache/airflow
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.