[ https://issues.apache.org/jira/browse/AIRFLOW-836?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Bolke de Bruin resolved AIRFLOW-836. ------------------------------------ Resolution: Fixed Fix Version/s: 1.9.0 Issue resolved by pull request #2054 [https://github.com/apache/incubator-airflow/pull/2054] > The paused and queryview endpoints are vulnerable to CSRF > --------------------------------------------------------- > > Key: AIRFLOW-836 > URL: https://issues.apache.org/jira/browse/AIRFLOW-836 > Project: Apache Airflow > Issue Type: Bug > Reporter: Alex Guziel > Assignee: Alex Guziel > Fix For: 1.9.0 > > > These endpoints use GET and are state-changing which is bad practice, and > allows CSRF -- This message was sent by Atlassian JIRA (v6.3.15#6346)