CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-32077: Apache Airflow: XSS vulnerability in Task Instance Log/Log Details

Description

Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs. 
Users are recommended to upgrade to version 2.9.1, which fixes this issue.

Classification

CVE ID: CVE-2024-32077

Affected Products

Vendor: Apache Software Foundation

Product: Apache Airflow

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.14% (probability of being exploited)

EPSS Percentile: 51.54% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://github.com/apache/airflow/pull/38882
https://lists.apache.org/thread/gsjmnrqb3m5fzp0vgpty1jxcywo91v77
http://www.openwall.com/lists/oss-security/2024/05/14/1

Timeline