CVE-2024-45034

CVE-2024-45034: Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes

Vendor Apache Software Foundation
Product Apache Airflow
Weakness CWE-250
Published September 7, 2024
Last update September 9, 2024

CVSS base score

What the vulnerability does

Description

Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by the scheduler, where the scheduler is not supposed to execute code submitted by the DAG author. Users are advised to upgrade to version 2.10.1 or later, which has fixed the vulnerability.

Key dates

Disclosure timeline

September 7, 2024 CVE published
September 9, 2024 Record updated