Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs. Users are recommended to upgrade to version 2.9.1, which fixes this issue.
2024-05-14T16:17:01.970
2025-03-27T20:15:26.090
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | airflow | 2.9.0 | Yes |
Application | apache | airflow | 2.9.0 | Yes |
Application | apache | airflow | 2.9.0 | Yes |
Application | apache | airflow | 2.9.0 | Yes |
Application | apache | airflow | 2.9.0 | Yes |
Application | apache | airflow | 2.9.0 | Yes |