CVE-2024-45498 is a critical vulnerability affecting Apache Airflow versions prior to 2.10.1, specifically within the example_inlet_event_extra.py DAG. An authenticated attacker with only DAG trigger permission can exploit this flaw to execute arbitrary commands, leading to high impact on confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, the CVSS score of 8.8 (HIGH) and FAUCET Risk Score of 72/100 highlight its severe potential. Organizations are advised to upgrade to Airflow 2.10.1 or later and avoid exposing example DAGs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.10.0CPE matchmatch criteria | cpe:2.3:a:apache:airflow:2.10.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.