← back
CVE-2022-24288observed exploitationCWE-78

Apache Airflow: RCE in example DAGs

62Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 78%
from disclosure to weapon
Published on NVDFeb 25
VulnCheck+651d
exploitation probability
78%top 1% of all CVEs
observed exploitation
yesVulnCheck
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.