oss-sec mailing list archives

CVE-2024-45034: Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes


From: Ephraim Anierobi <ephraimanierobi () apache org>
Date: Fri, 06 Sep 2024 16:45:30 +0000

Severity: important

Affected versions:

- Apache Airflow before 2.10.1

Description:

Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG 
folder and get it executed by the scheduler, where the scheduler is not supposed to execute code submitted by the DAG 
author. 
Users are advised to upgrade to version 2.10.1 or later, which has fixed the vulnerability.

Credit:

Seokchan Yoon: https://github.com/ch4n3-yoon (finder)
Amogh Desai (remediation developer)

References:

https://github.com/apache/airflow/pull/41672
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-45034


Current thread: