PT-2020-6686 · Redis+2 · Redis+2

Adam Goldschmit

·

Published

2020-07-13

·

Updated

2024-03-06

·

CVE-2020-11982

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 1.10.10 and below
Description The issue is related to the deserialization of untrusted data in Apache Airflow, which can lead to remote code execution. An attacker, acting remotely, can exploit this issue by inserting a malicious payload directly into the broker, such as Redis or RabbitMQ, when using CeleryExecutor. This can result in the execution of arbitrary code or a denial of service.
Recommendations For Apache Airflow versions 1.10.10 and below, consider updating to a version that includes a fix for this issue, although the specific fixed version is not provided in the available data. As a temporary workaround, restrict access to the broker to minimize the risk of exploitation. Avoid using CeleryExecutor until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2022-04611
BIT-AIRFLOW-2020-11982
CVE-2020-11982
GHSA-9G2W-5F3V-MFMM
PYSEC-2020-16

Affected Products

Apache Airflow
Rabbitmq
Redis