CVE-2022-40127: fallo de gravedad alta en Apache Airflow
Apache Airflow <2.4.0 has an RCE in a bash example
Publicada el · Actualizada el
58Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendcvss 8.8epss 86%
probabilidad de explotación
86%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Apache Software Foundation · Apache AirflowCVEs relacionadas — Apache Airflow
En el mismo producto, de las más peligrosas a las menos.
CVE-2020-11978HIGHCVE-2020-11978EPSS 99.2%KEVCVE-2022-45402MEDIUMApache Airflow: Open redirect during loginEPSS 81.8%CVE-2021-38540—Apache Airflow: Variable Import endpoint missed authentication checkEPSS 80.9%CVE-2022-24288—Apache Airflow: RCE in example DAGsEPSS 77.9%CVE-2020-11981—CVE-2020-11981EPSS 36.5%CVE-2020-17526—CVE-2020-17526EPSS 23.3%