ApatchMe - Authenticated Stored XSS Vulnerability in AWS and GCP Apache Airflow Services
Tenable
NOVEMBER 4, 2023
Unpatched Apache Airflow instances used in Amazon Web Services (AWS) and Google Cloud Platform (GCP) allow an exploitable stored XSS through the task instance details page. However, the managed services provided by AWS and GCP were utilizing an outdated, unpatched version. We thank AWS and GCP for their cooperation and quick response.
Let's personalize your content