PT-2024-24381 · Apache · Apache Airflow

Jens Scheffler

+1

·

Published

2024-05-14

·

Updated

2024-12-11

·

CVE-2024-32077

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow version 2.9.0
Description The issue allows an authenticated attacker to inject malicious data into the task instance logs. This is a critical security vulnerability that enables attackers to inject data into the task instance logs.
Recommendations For Apache Airflow version 2.9.0, upgrade to version 2.9.1 to fix the issue. As a temporary workaround, consider restricting access to the task instance logs until the upgrade is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2024-32077
CVE-2024-32077
GHSA-52GM-QMG3-R4QP
PYSEC-2024-264

Affected Products

Apache Airflow