A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
Add your gear to cvedb and we'll alert you only when apache ships something exploited.
Check my exposure →This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.