CVE-2022-40127: high-severity vulnerability in Apache Airflow
Apache Airflow <2.4.0 has an RCE in a bash example
Published · Updated
58Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 8.8epss 86%
exploitation probability
86%top 1% of all CVEs
observed exploitation
nono source reports it
A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Apache Software Foundation · Apache AirflowRelated CVEs — Apache Airflow
In the same product, most dangerous first.
CVE-2020-11978HIGHCVE-2020-11978EPSS 99.2%KEVCVE-2022-45402MEDIUMApache Airflow: Open redirect during loginEPSS 81.8%CVE-2021-38540—Apache Airflow: Variable Import endpoint missed authentication checkEPSS 80.9%CVE-2022-24288—Apache Airflow: RCE in example DAGsEPSS 77.9%CVE-2020-11981—CVE-2020-11981EPSS 36.5%CVE-2020-17526—CVE-2020-17526EPSS 23.3%