CVE-2024-32077
ADVISORY - githubSummary
Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs. Users are recommended to upgrade to version 2.9.1, which fixes this issue.
EPSS Score: 0.03397 (0.875)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ADVISORY - github
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
NIST
CREATED
UPDATED
ADVISORY IDCVE-2024-32077
EXPLOITABILITY SCORE
2.3
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5.4mediumGitHub
CREATED
UPDATED
ADVISORY IDGHSA-52gm-qmg3-r4qp
EXPLOITABILITY SCORE
2.3
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5.4mediumPypA
CREATED
UPDATED
ADVISORY ID
PYSEC-2024-264
EXPLOITABILITY SCORE
2.3
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
5.4mediumBitnami
CREATED
UPDATED
ADVISORY ID
BIT-airflow-2024-32077
EXPLOITABILITY SCORE
2.3
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-