Lucene search

K
cveApacheCVE-2024-45498
HistorySep 07, 2024 - 8:15 a.m.

CVE-2024-45498

2024-09-0708:15:11
CWE-116
apache
web.nvd.nist.gov
24
apache airflow
example dag
vulnerability

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.5%

Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with only DAG trigger permission to execute arbitrary commands. If you used that example as the base of your DAGs - please review if you have not copied the dangerous example; see https://github.com/apache/airflow/pull/41873 Β for more information. We recommend against exposing the example DAGs in your deployment. If you must expose the example DAGs, upgrade Airflow to version 2.10.1 or later.

Affected configurations

Vulners
Node
apacheairflowRange≀2.10.0
VendorProductVersionCPE
apacheairflow*cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "collectionURL": "https://pypi.python.org",
    "defaultStatus": "unaffected",
    "packageName": "apache-airflow",
    "product": "Apache Airflow",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "2.10.0",
        "versionType": "semver"
      }
    ]
  }
]

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.5%