DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-41937

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-41937

CGA ID

CGA-6h8r-33x9-cmw8

Severity

6.1

Medium

CVSS V3

Description

Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user to click the provider link. Users should upgrade to 2.10.0 or later, which fixes this vulnerability.

References

  • https://images.chainguard.dev/security/CGA-6h8r-33x9-cmw8

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images