NA

CVE-2024-32077

Published: 14/05/2024 Updated: 14/05/2024

Vulnerability Summary

Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated malicious user to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2024-32077: Apache Airflow: XSS vulnerability in Task Instance Log/Log Details <!--X-Subject-Header-End--> <!--X-Head-of-M ...