airflow-2
Chainguard
7.4
CVSS V3
Status
Impact
The ecdsa library vulnerability (CVE-2024-23342) is a timing-based side-channel attack (Minerva attack) affecting versions 0.19.1 and prior. Currently there is no patched version available from the upstream ecdsa maintainers. Airflow-2 depends on ecdsa 0.19.1 as a transitive dependency. We are waiting for the ecdsa project to release a fixed version before this can be resolved.
Status