Apache Airflow vulnerable to CSRF Attacks
High severity
GitHub Reviewed
Published
Apr 18, 2019
to the GitHub Advisory Database
•
Updated Sep 12, 2024
Description
Published to the GitHub Advisory Database
Apr 18, 2019
Reviewed
Jun 16, 2020
Last updated
Sep 12, 2024
A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site request forgery attacks.
References