Apache Airflow: RCE in example DAGs
62Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 78%
from disclosure to weapon
Published on NVDFeb 25
VulnCheck+651d
exploitation probability
78%top 1% of all CVEs
observed exploitation
yesVulnCheck
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
Affected products
Apache Software Foundation · Apache Airflow