CVE-2019-12398: Cross-site Scripting
(updated )
In Apache Airflow when running with the classic
UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new “RBAC” UI is unaffected.
References
Detect and mitigate CVE-2019-12398 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →