CVE-2024-32077

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
14/05/2024
Last modified:
27/03/2025

Description

Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs. <br /> Users are recommended to upgrade to version 2.9.1, which fixes this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:airflow:2.9.0:-:*:*:*:*:*:*
cpe:2.3:a:apache:airflow:2.9.0:beta1:*:*:*:*:*:*
cpe:2.3:a:apache:airflow:2.9.0:beta2:*:*:*:*:*:*
cpe:2.3:a:apache:airflow:2.9.0:rc1:*:*:*:*:*:*
cpe:2.3:a:apache:airflow:2.9.0:rc2:*:*:*:*:*:*
cpe:2.3:a:apache:airflow:2.9.0:rc3:*:*:*:*:*:*