FixVibe

high

Apache Airflow Improper Output Encoding (CVE-2024-45498)

Apache Airflow 2.10.0 shipped an example-DAG issue tracked as CVE-2024-45498 / GHSA-c392-whpc-vfpr. FixVibe GitHub repo scans flag the affected apache-airflow dependency.

CVE-2024-45498GHSA-c392-whpc-vfprGHSA-c392-whpc-vfprCWE-116

Impact

CVE-2024-45498 affects the example_inlet_event_extra.py example DAG shipped with Apache Airflow 2.10.0. Advisory sources describe a command-execution risk for an authenticated user who has DAG trigger permission when the affected example or copied DAG code is present [S2][S4]. Airflow 2.10.1 is the fixed release, and OSV also lists the 2.10.1 release candidate as affected [S3].

Root Cause

The issue is tracked as CWE-116, improper encoding or escaping of output [S1]. In practical deployment terms, the risk is tied to the example DAG code path and the permissions and deployment choices around loaded DAGs, not to every Airflow UI response [S4][S5].

Covered by FixVibe

FixVibe's GitHub repo scans flag Python projects that depend on the apache-airflow release associated with this advisory, and show the version and file to upgrade.

Remediation

Upgrade Apache Airflow to 2.10.1 or a later maintained release, regenerate the active lockfile or constraints file, and rebuild every scheduler, webserver, worker, CI, notebook, and container image that installs Airflow [S2][S3]. Keep example DAGs disabled in production and remove or update any copied example_inlet_event_extra.py DAGs before redeploying.