/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-9693-6pc2-x32q

Published

Last updated

https://images.chainguard.dev/security/CGA-9693-6pc2-x32q
Package

airflow-2

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2024-39338
  • GHSA-8hc4-vh64-cxmj

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-39338

Updates

Status

Pending upstream fix

Impact

The axios dependency needs to be bumped by upstream as upgrading it to the latest version would bump it by several versions and would break the application in unpredictable ways.


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing