PT-2022-5600 · Apache · Apache Airflow

L3Yx

·

Published

2022-11-14

·

Updated

2026-02-20

·

CVE-2022-40127

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.4.0
Description A vulnerability in Example Dags of Apache Airflow is related to incorrect management of code generation. This issue allows an attacker with UI access who can trigger DAGs to execute arbitrary commands via the manually provided run id parameter. The exploitation of this vulnerability may enable a remote attacker to execute arbitrary commands.
Recommendations For versions prior to 2.4.0, update to version 2.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the run id parameter in the affected DAGs to minimize the risk of exploitation. Additionally, limiting UI access to trusted users can help reduce the attack surface.

Exploit

Fix

OS Command Injection

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2022-06963
BIT-AIRFLOW-2022-40127
CVE-2022-40127
GHSA-6PW3-8H9W-32GC
PYSEC-2022-42982

Affected Products

Apache Airflow