Vulnerability CVE-2023-29247


Published: 2023-05-08

Description:
Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.


Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://github.com/apache/airflow/pull/30779
https://github.com/apache/airflow/pull/30447
https://lists.apache.org/thread/kqf5lxmko133780clsp827xfsh4xd3fl

Copyright 2026, cxsecurity.com

 

Back to Top