CVE-2020-11981
30Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 37%
exploitation probability
37%top 2% of all CVEs
observed exploitation
nono source reports it
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.
Affected products
Apache Software Foundation · Apache Airflow