Cross-Site Request Forgery (CSRF) in Apache Airflow
High severity
GitHub Reviewed
Published
Jan 25, 2019
to the GitHub Advisory Database
•
Updated Sep 11, 2024
Description
Published to the GitHub Advisory Database
Jan 25, 2019
Reviewed
Jun 16, 2020
Last updated
Sep 11, 2024
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
References