Known vulnerabilities in Apache Airflow - page 2

Software CPE: cpe:2.3:a:apache_foundation:apache_airflow:*:*:*:*:*:*:*:*
Total vulnerabilities: 79
Public exploits: 4
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Airflow Apache Airflow is affected by 79 known vulnerabilities: 8 high, 22 medium, 49 low Critical High Medium Low

Vulnerabilities (79)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU120168 - Externally-generated error message containing sensitive information
CVE-2025-65995
CWE-211 Medium
No
No
3.1.4 17.12.2025 SB2025121728
#VU100568 - Information Exposure Through Log Files
CVE-2024-45784
CWE-532 Low
No
No
2.10.3 15.11.2024 SB2024111110
#VU100210 - Information Exposure Through Log Files
CVE-2024-50378
CWE-532 Low
No
No
2.10.3 11.11.2024 SB2024111110
#VU96967 - Permissions, Privileges, and Access Controls
CVE-2024-45034
CWE-264 Medium
No
No
2.10.1 10.09.2024 SB2024091005
#VU96966 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-45498
CWE-78 Low
No
No
2.10.1 10.09.2024 SB2024091005
#VU96463 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-41937
CWE-79 Low
No
No
2.10.0 22.08.2024 SB2024082283
#VU92129 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-32077
CWE-79 Low
No
No
2.9.1 14.06.2024 SB2024061425
#VU92128 - Use of Web Browser Cache Containing Sensitive Information
CVE-2024-25142
CWE-525 Medium
No
No
2.9.2 14.06.2024 SB2024061423
#VU87569 - Improper Access Control
CVE-2024-28746
CWE-284 Low
No
No
2.8.3 15.03.2024 SB2024031532
#VU86995 - Improper Access Control
CVE-2024-26280
CWE-284 Low
No
No
2.8.2 04.03.2024 SB2024030133
#VU86952 - Improper Authentication
CVE-2024-25128
CWE-287 High
No
No
2.8.2 01.03.2024 SB2024030133
#VU86951 - Permissions, Privileges, and Access Controls
CVE-2024-27906
CWE-264 Low
No
No
2.8.2 01.03.2024 SB2024030133
#VU85800 - Permissions, Privileges, and Access Controls
CVE-2023-50944
CWE-264 Low
No
No
2.8.1 25.01.2024 SB2024012523
#VU85798 - Security Features
CVE-2023-50943
CWE-254 Low
No
No
2.8.1 25.01.2024 SB2024012523
#VU85793 - Information Exposure Through Log Files
CVE-2023-51702
CWE-532 Low
No
No
2.6.1 25.01.2024 SB2024012516
#VU85564 - Deserialization of Untrusted Data
CVE-2023-47248
CWE-502 High
No
No
2.8.1 18.01.2024 SB2024011810
SB2024011817
SB2024011818
and 9 more
#VU83623 - Improper Access Control
CVE-2023-40712
CWE-284 Low
No
No
2.7.1 01.12.2023 SB2023120161
SB2023120163
#VU83544 - Improper Access Control
CVE-2023-47037
CWE-284 Low
No
No
2.7.3 28.11.2023 SB2023112860
SB2023120163
#VU83023 - Improper Access Control
CVE-2023-42781
CWE-284 Low
No
No
2.7.3 13.11.2023 SB2023111326
#VU83022 - Improper Access Control
CVE-2023-42663
CWE-284 Low
No
No
2.7.2 13.11.2023 SB2023111325


Showing elements 21 - 40 out of 79