​
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-41937

Published

Last updated

https://nvd.nist.gov/vuln/detail/CVE-2024-41937

Severity

6.1

Medium

CVSS V3

Description

Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user to click the provider link. Users should upgrade to 2.10.0 or later, which fixes this vulnerability.

References

  • https://github.com/advisories/GHSA-w7cp-g8v7-r54m

Affected packages


Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private Policy
Terms of Use

Product

Chainguard Images