PT-2024-24381 · Apache · Apache Airflow

·

CVE-2024-32077

·

Published

2024-05-14

·

Updated

2024-12-11

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow version 2.9.0
Description The issue allows an authenticated attacker to inject malicious data into the task instance logs. This is a critical security vulnerability that enables attackers to inject data into the task instance logs.
Recommendations For Apache Airflow version 2.9.0, upgrade to version 2.9.1 to fix the issue. As a temporary workaround, consider restricting access to the task instance logs until the upgrade is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2024-32077
CVE-2024-32077
GHSA-52GM-QMG3-R4QP
PYSEC-2024-264

Affected Products

Apache Airflow