Severity: important

Affected versions:

- Apache Airflow before 2.10.1

Description:

Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG 
authors to add local settings to the DAG folder and get it executed by the 
scheduler, where the scheduler is not supposed to execute code submitted by the 
DAG author. 
Users are advised to upgrade to version 2.10.1 or later, which has fixed the 
vulnerability.

Credit:

Seokchan Yoon: https://github.com/ch4n3-yoon (finder)
Amogh Desai (remediation developer)

References:

https://github.com/apache/airflow/pull/41672
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-45034

Reply via email to