Junglewise Threat Intelligence

CVE-2024-32077: Apache Airflow XSS in Task Instance Log

CVE-2024-32077 · Severity: medium · CVSS 5.4 · Published 2024-05-14

Technologies: Apache Airflow, apache-airflow (PyPI). Vendors: Apache, PyPI.

Executive brief

Apache Airflow, a platform used to schedule and monitor complex workflows, contains a security flaw in how it displays task logs. An authorized user could potentially inject malicious scripts into these logs, which would then execute in the browser of another user viewing the log details. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Airflow 2.9.0 due to improper neutralization of user-controllable input before it is rendered in the Task Instance Log and Log Details web interfaces (CWE-79). The root cause involves how the UI handles log data, specifically related to linkification and ANSI color processing. An authenticated attacker with the ability to influence task output can inject malicious scripts into the logs. When a victim (such as an administrator) views these logs, the script executes in their browser context. This can lead to session hijacking or unauthorized configuration changes. The issue is resolved in version 2.9.1 by disabling problematic link generation in the ansi_up library and fixing JavaScript event handlers.

Affected products

  • Apache Airflow 2.9.0

Timeline

  • 2024-04-10: patched: Fix merged into main branch via PR 38882
  • 2024-05-14: disclosed: Initial advisory and CVE publication

References

Related threats