Skip to content
Apache AirflowGHSA-c392-whpc-vfpr

Apache Airflow vulnerable to Improper Encoding or Escaping of Output

High8.8CVE-2024-45498 · Published Sep 7, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
>= 2.10.0, < 2.10.12.10.1
Details and references

Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with only DAG trigger permission to execute arbitrary commands. If you used that example as the base of your DAGs - please review if you have not copied the dangerous example; see https://github.com/apache/airflow/pull/41873  for more information. We recommend against exposing the example DAGs in your deployment. If you must expose the example DAGs, upgrade Airflow to version 2.10.1 or later.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-116
Also known as
BIT-airflow-2024-45498, CVE-2024-45498, PYSEC-2024-266

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Sep 72024Apache Airflow vulnerable to Execution with Unnecessary Privileges
CVE-2024-45034High8.8fixed in 2.10.1
Aug 212024Apache Airflow Cross-site Scripting Vulnerability
CVE-2024-41937Medium6.1fixed in 2.10.0
Aug 52024Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB.
CVE-2024-42447Critical9.8no fix yet
Jul 172024Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
CVE-2024-39877High8.8fixed in 2.9.3
Jul 172024Apache Airflow Potential Cross-site Scripting Vulnerability
CVE-2024-39863Medium5.4fixed in 2.9.3
Nov 82024Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
CVE-2024-50378Low6.5fixed in 2.10.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.