Severity: low

Affected versions:

- Apache Airflow before 2.9.3

Description:

Apache Airflow versions before 2.9.3 have a vulnerability that allows an 
authenticated attacker to inject a malicious link when installing a provider. 
Users are recommended to upgrade to version 2.9.3, which fixes this issue.

Credit:

Seokchan Yoon (https://github.com/ch4n3-yoon) (finder)
Amogh Desai (remediation developer)

References:

https://github.com/apache/airflow/pull/40475
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-39863

Reply via email to