DirectorySecurity Advisories
Sign In
Security Advisories

CGA-6h8r-33x9-cmw8

Published

Last updated

https://images.chainguard.dev/security/CGA-6h8r-33x9-cmw8
Package

airflow

Latest Update
Fixed
Fixed Version

2.10.0-r0

Aliases
  • CVE-2024-41937
  • GHSA-w7cp-g8v7-r54m

Severity

6.1

Medium

CVSS V3

Summary

Apache Airflow Cross-site Scripting Vulnerability

Description

Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user to click the provider link. Users should upgrade to 2.10.0 or later, which fixes this vulnerability.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images