CVE-2024-56373 Details
Description
DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able to do, leading to potentially remote code execution in the context of web-server (server-side) as a result of a user viewing historical task information. The functionality responsible for that (log template history) has been disabled by default in 2.11.1 and users should upgrade to Airflow 3 if they want to continue to use log template history. They can also manually modify historical log file names if they want to see historical logs that were generated before the last log template change.
A vulnerability in Apache Airflow versions prior to 2.11.1 allows DAG Authors to manipulate the database and execute arbitrary code in the web server context. This issue arises when a user views historical task information, potentially leading to remote code execution on the server side. The vulnerability is related to the log template history feature, which has been disabled by default in Airflow 2.11.1. Users who wish to continue using log template history should upgrade to Airflow 3 or manually adjust historical log file names to access logs generated before the last log template change.
Users are advised to upgrade to Apache Airflow 3. If upgrading is not possible, historical log file names can be manually modified to access logs generated before the last log template change.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/02/23/3 | CVE | Mailing ListThird Party Advisory |
| https://github.com/apache/airflow/pull/61880 | [email protected] | Issue Tracking |
| https://lists.apache.org/thread/2vrmrhcht6g7cp5yjxpnrk2wtrncm6cy | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache airflow | < 2.11.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 24, 2026 | Initial Analysis | [email protected] |
| Feb 24, 2026 | CVE Modified | CISA-ADP |
| Feb 24, 2026 | CVE Modified | CVE |
| Feb 24, 2026 | New CVE Received | [email protected] |