CVE-2024-56373
Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information
描述
DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able to do, leading to potentially remote code execution in the context of web-server (server-side) as a result of a user viewing historical task information. The functionality responsible for that (log template history) has been disabled by default in 2.11.1 and users should upgrade to Airflow 3 if they want to continue to use log template history. They can also manually modify historical log file names if they want to see historical logs that were generated before the last log template change.
如何修補 CVE-2024-56373
要修補 CVE-2024-56373,請將受影響套件升級到下列已修補版本。
- —升級至 2.11.1 或更新版本
- —升級至 2.11.1 或更新版本
- —升級至 2.11.1 或更新版本
CVE-2024-56373 正在被利用嗎?
低 — EPSS 為 1.1%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 2.11.1
- from 0, < 2.11.1
- from 0, < 2.11.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.4 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |