CVE-2024-56373 — DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able to — CVE Database · The Intelligence Room