Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-39877


Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Security model. Users should upgrade to version 2.9.3 or later which has removed the vulnerability.


Published

2024-07-17T08:15:02.073

Last Modified

2024-11-21T09:28:28.910

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-94
  • Type: Secondary
    CWE-277

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache airflow < 2.9.3 Yes

References