Skip to content
Apache AirflowGHSA-92xg-gmrq-5c3w

Apache Airflow vulnerable to Execution with Unnecessary Privileges

High8.8CVE-2024-45034 · Published Sep 7, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.10.12.10.1
Details and references

Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by the scheduler, where the scheduler is not supposed to execute code submitted by the DAG author. Users are advised to upgrade to version 2.10.1 or later, which has fixed the vulnerability.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-250
Also known as
BIT-airflow-2024-45034, CVE-2024-45034, PYSEC-2024-212

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Sep 72024Apache Airflow vulnerable to Improper Encoding or Escaping of Output
CVE-2024-45498High8.8fixed in 2.10.1
Aug 212024Apache Airflow Cross-site Scripting Vulnerability
CVE-2024-41937Medium6.1fixed in 2.10.0
Aug 52024Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB.
CVE-2024-42447Critical9.8no fix yet
Jul 172024Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
CVE-2024-39877High8.8fixed in 2.9.3
Jul 172024Apache Airflow Potential Cross-site Scripting Vulnerability
CVE-2024-39863Medium5.4fixed in 2.9.3
Nov 82024Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
CVE-2024-50378Low6.5fixed in 2.10.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.