« Volver al listado

CVE-2024-32077

Estado: ModificadaMedia (5.4)—

Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-32077",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-32077",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-14T18:35:34.470154Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache Airflow",
          "versions": [
            {
              "status": "affected",
              "version": "2.9.0",
              "lessThan": "2.9.1",
              "versionType": "semver"
            }
          ],
          "packageName": "apache-airflow",
          "collectionURL": "https://pypi.python.org",
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*"
          ],
          "vendor": "apache",
          "product": "airflow",
          "versions": [
            {
              "status": "affected",
              "version": "2.9.0"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-14T16:17:01.970",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/05/14/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://github.com/apache/airflow/pull/38882",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread/gsjmnrqb3m5fzp0vgpty1jxcywo91v77",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/05/14/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/apache/airflow/pull/38882",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread/gsjmnrqb3m5fzp0vgpty1jxcywo91v77",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs. \nUsers are recommended to upgrade to version 2.9.1, which fixes this issue."
    },
    {
      "lang": "es",
      "value": "Apache Airflow versión 2.9.0 tiene una vulnerabilidad que permite a un atacante autenticado inyectar datos maliciosos en los registros de instancias de tareas. Se recomienda a los usuarios actualizar a la versión 2.9.1, que soluciona este problema."
    }
  ],
  "lastModified": "2026-06-17T07:29:12.820",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:airflow:2.9.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "67713622-C581-4BC0-B7B1-0FE3DD3A55C0"
            },
            {
              "criteria": "cpe:2.3:a:apache:airflow:2.9.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B4F89EF-D541-4D17-89EC-DBC97A3399AA"
            },
            {
              "criteria": "cpe:2.3:a:apache:airflow:2.9.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADBE102C-D1FE-4D57-9E00-C9A851515063"
            },
            {
              "criteria": "cpe:2.3:a:apache:airflow:2.9.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3186E514-8CA2-48E3-8B2B-3CD4D34447F5"
            },
            {
              "criteria": "cpe:2.3:a:apache:airflow:2.9.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62AA6481-91E2-43C6-BE9A-B809E2A723D2"
            },
            {
              "criteria": "cpe:2.3:a:apache:airflow:2.9.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F748994-9CDA-4ACE-A7DC-7EF6D1896082"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}