Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-6pw3-8h9w-32gc: Apache Airflow vulnerable to OS Command Injection via example DAGs

A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow versions prior to 2.4.0.

ghsa
#vulnerability#apache#git

Apache Airflow vulnerable to OS Command Injection via example DAGs

Moderate severity GitHub Reviewed Published Nov 14, 2022 • Updated Nov 16, 2022

Related news

CVE-2022-40127: Change the template to use human readable task_instance description by potiuk · Pull Request #25960 · apache/airflow

A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.