Headline
GHSA-6pw3-8h9w-32gc: Apache Airflow vulnerable to OS Command Injection via example DAGs
A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow versions prior to 2.4.0.
Apache Airflow vulnerable to OS Command Injection via example DAGs
Moderate severity GitHub Reviewed Published Nov 14, 2022 • Updated Nov 16, 2022
Related news
CVE-2022-40127: Change the template to use human readable task_instance description by potiuk · Pull Request #25960 · apache/airflow
A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.