Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-32077


Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.


Published

2024-05-14T16:17:01.970

Last Modified

2025-03-27T20:15:26.090

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache airflow 2.9.0 Yes
Application apache airflow 2.9.0 Yes
Application apache airflow 2.9.0 Yes
Application apache airflow 2.9.0 Yes
Application apache airflow 2.9.0 Yes
Application apache airflow 2.9.0 Yes

References