Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.
Users are recommended to upgrade to version 2.9.1, which fixes this issue.
CVE ID: CVE-2024-32077
Vendor: Apache Software Foundation
Product: Apache Airflow
EPSS Score: 0.14% (probability of being exploited)
EPSS Percentile: 51.54% (scored less or equal to compared to others)
EPSS Date: 2025-03-14 (when was this score calculated)