Apache Software Foundation Airflow 2.9.0 Release Candidate 2

CPE Details

Apache Software Foundation Airflow 2.9.0 Release Candidate 2
2.9.0
2024-07-18
17h05 +00:00
2024-07-18
17h05 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:apache:airflow:2.9.0:rc2:*:*:*:*:*:*

Informations

Vendor

apache

Product

airflow

Version

2.9.0

Update

rc2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-41937 2024-08-21 15h31 +00:00 Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user to click the provider link. Users should upgrade to 2.10.0 or later, which fixes this vulnerability.
6.1
Medium
CVE-2024-39877 2024-07-17 07h54 +00:00 Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Security model. Users should upgrade to version 2.9.3 or later which has removed the vulnerability.
8.8
High
CVE-2024-39863 2024-07-17 07h53 +00:00 Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue.
8.1
High
CVE-2024-25142 2024-06-14 08h25 +00:00 Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.
5.5
Medium
CVE-2024-32077 2024-05-14 10h43 +00:00 Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.
5.4
Medium