PT-2024-31385 · Apache · Apache Airflow

Amogh Desai

+1

·

Published

2024-09-06

·

Updated

2026-02-20

·

CVE-2024-45034

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.10.1
Description The issue allows DAG authors to add local settings to the DAG folder and get it executed by the scheduler, where the scheduler is not supposed to execute code submitted by the DAG author. Users are advised to upgrade to a fixed version.
Recommendations For Apache Airflow versions prior to 2.10.1, upgrade to version 2.10.1 or later to fix the vulnerability. As a temporary workaround, consider restricting access to the DAG folder to prevent unauthorized execution of local settings.

Fix

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2024-45034
CVE-2024-45034
GHSA-92XG-GMRQ-5C3W
PYSEC-2024-212

Affected Products

Apache Airflow