Page 15 of 71 results (0.003 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above. Se ha descubierto Cross-Site Scripting (XSS) en ciertas páginas 404 que podría explotarse para realizar un ataque de Cross-Site Scripting (XSS). • https://lists.apache.org/thread.html/2c72480c76619c5e7793f0d213c34082f0598eaa4d212172f068940f%40%3Cdev.airflow.apache.org%3E • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •