CVE-2024-32077

MEDIUM5.4EPSS 3.4%

Apache Airflow: XSS vulnerability in Task Instance Log/Log Details

Published: 5/14/2024Modified: 5/21/2026

Description

Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (6)