id: PYSEC-2019-148 details: In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow. affected: - package: name: apache-airflow ecosystem: PyPI purl: pkg:pypi/apache-airflow ranges: - type: ECOSYSTEM events: - introduced: '0' - fixed: 1.9.0 versions: - 1.8.1 - 1.8.2 - 1.8.2rc1 references: - type: WEB url: https://lists.apache.org/thread.html/ade4d54ebf614f68dc81a08891755e60ea58ba88e0209233eeea5f57@%3Cdev.airflow.apache.org%3E - type: ADVISORY url: https://github.com/advisories/GHSA-68wv-rjrm-576p aliases: - CVE-2017-17835 - GHSA-68wv-rjrm-576p modified: '2021-07-05T00:01:17.030004Z' published: '2019-01-23T17:29:00Z'