High severity8.8NVD Advisory· Published Jul 17, 2024· Updated Jun 17, 2026
CVE-2024-39877
CVE-2024-39877
Description
Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Security model. Users should upgrade to version 2.9.3 or later which has removed the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflowPyPI | >= 2.4.0, < 2.9.3 | 2.9.3 |
Affected products
10- ghsa-coords8 versionspkg:pypi/apache-airflowpkg:apk/wolfi/airflow-compatpkg:bitnami/airflowpkg:apk/chainguard/airflow-bitnami-compatpkg:apk/wolfi/airflow-bitnami-compatpkg:apk/chainguard/airflowpkg:apk/wolfi/airflowpkg:apk/chainguard/airflow-compat
>= 2.4.0, < 2.9.3+ 7 more
- (no CPE)range: >= 2.4.0, < 2.9.3
- (no CPE)range: < 2.9.3-r0
- (no CPE)range: >= 2.4.0, < 2.9.3
- (no CPE)range: < 2.9.3-r0
- (no CPE)range: < 2.9.3-r0
- (no CPE)range: < 2.9.3-r0
- (no CPE)range: < 2.9.3-r0
- (no CPE)range: < 2.9.3-r0
Patches
Vulnerability mechanics
References
7- github.com/apache/airflow/pull/40522nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-g5hv-r743-v8pmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-39877ghsaADVISORY
- www.openwall.com/lists/oss-security/2024/07/16/7nvdWEB
- github.com/apache/airflow/commit/8159f6e24704f5e0e3b3217cf79ecf5083dce531ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2024-190.yamlghsaWEB
- lists.apache.org/thread/1xhj9dkp37d6pzn24ll2mf94wbqnb2y1nvdMailing ListWEB
News mentions
0No linked articles in our index yet.