Vulnerabilities > CVE-2020-17513 - Server-Side Request Forgery (SSRF) vulnerability in Apache Airflow

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
apache
CWE-918

Summary

In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.

Common Weakness Enumeration (CWE)