{"id":"CVE-2021-45229","aliases":["BIT-airflow-2021-45229","GHSA-65xw-pcqw-hjrh","PYSEC-2022-29"],"url":"https://o3.security/vulnerability/CVE-2021-45229","summary":"Apache Airflow Cross-site Scripting Vulnerability","details":"It was discovered that the \"Trigger DAG with config\" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.","published":"2022-02-25T09:15:06.760Z","modified":"2026-08-07T17:03:14.043541Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"apache-airflow","fixedVersion":"2.2.4rc1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread/phx76cgtmhwwdy780rvwhobx8qoy4bnk"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T17:03:14.043541Z"}}