CVE-2024-39877: Apache Airflow: DAG Author Code Execution possibility in airflow-scheduler
Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a docmd parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Security model. Users should upgrade to version 2.9.3 or later which has removed the vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39877?
CVE-2024-39877 is a high-severity vulnerability affecting Apache Airflow versions 2.4.0 to 2.9.2.
How do I fix CVE-2024-39877?
To fix CVE-2024-39877, upgrade Apache Airflow to version 2.9.3 or later.
Who is affected by CVE-2024-39877?
CVE-2024-39877 affects authenticated DAG authors using Apache Airflow versions 2.4.0 through 2.9.2.
What type of vulnerability is CVE-2024-39877?
CVE-2024-39877 is a code execution vulnerability that allows crafted input to execute arbitrary code in the scheduler context.
Is there a workaround for CVE-2024-39877?
Currently, there are no known workarounds for CVE-2024-39877, so upgrading to the fixed version is essential.