Medium severity6.1NVD Advisory· Published Feb 25, 2022· Updated Jun 17, 2026
CVE-2021-45229
CVE-2021-45229
Description
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the origin query argument. This issue affects Apache Airflow versions 2.2.3 and below.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflowPyPI | < 2.2.4rc1 | 2.2.4rc1 |
Affected products
4- osv-coords2 versions
< 2.2.4+ 1 more
- (no CPE)range: < 2.2.4
- (no CPE)range: < 2.2.4rc1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-65xw-pcqw-hjrhghsaADVISORY
- lists.apache.org/thread/phx76cgtmhwwdy780rvwhobx8qoy4bnknvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-45229ghsaADVISORY
- github.com/apache/airflow/commit/628aa1f99c865d97d0b1c7c76e630e43a7b8d319ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2022-29.yamlghsaWEB
News mentions
0No linked articles in our index yet.