PT-2022-16585 · Apache · Apache Airflow

Kai Zhao

·

Published

2022-02-25

·

Updated

2024-03-06

·

CVE-2022-24288

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.2.4
Description The issue arises from some example DAGs in Apache Airflow not properly sanitizing user-provided params, making them susceptible to OS Command Injection from the web UI.
Recommendations For versions prior to 2.2.4, update to version 2.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the web UI to minimize the risk of exploitation.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2022-24288
CVE-2022-24288
GHSA-3V7G-4PG3-7R6J
PYSEC-2022-30

Affected Products

Apache Airflow