PT-2022-5600 · Apache · Apache Airflow
L3Yx
·
Published
2022-11-14
·
Updated
2026-02-20
·
CVE-2022-40127
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions prior to 2.4.0
Description
A vulnerability in Example Dags of Apache Airflow is related to incorrect management of code generation. This issue allows an attacker with UI access who can trigger DAGs to execute arbitrary commands via the manually provided
run id parameter. The exploitation of this vulnerability may enable a remote attacker to execute arbitrary commands.Recommendations
For versions prior to 2.4.0, update to version 2.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the
run id parameter in the affected DAGs to minimize the risk of exploitation. Additionally, limiting UI access to trusted users can help reduce the attack surface.Exploit
Fix
OS Command Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Airflow