⚠ Actively exploited
Added to CISA KEV on 2022-01-18. Federal agencies required to patch by 2022-07-18. Required action: Apply updates per vendor instructions..

CVE-2020-11978OS Command Injection in Apache Airflow

Severity
8.8HIGHNVD
EPSS
94.3%
top 0.05%
CISA KEV
KEV
Added 2022-01-18
Due 2022-07-18
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJul 17
KEV addedJan 18
Latest updateFeb 1
KEV dueJul 18
CISA Required Action: Apply updates per vendor instructions.

Description

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5apache_software_foundation/apache_airflow1.10.10 and below
NVDapache/airflow< 1.10.11

🔴Vulnerability Details

5
OSV
Remote code execution (RCE) in Apache Airflow2020-07-27
GHSA
Remote code execution (RCE) in Apache Airflow2020-07-27
OSV
CVE-2020-11978: An issue was found in Apache Airflow versions 12020-07-17
CVEList
CVE-2020-11978: An issue was found in Apache Airflow versions 12020-07-16
VulnCheck
Apache Airflow Command Injection2020

💥Exploits & PoCs

3
Exploit-DB
Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution2021-06-02
Nuclei
Apache Airflow <=1.10.10 - Remote Code Execution
Metasploit
Apache Airflow 1.10.10 - Example DAG Remote Code Execution

🔍Detection Rules

2
Suricata
ET EXPLOIT Possible Apache Airflow DAG Example RCE Attempt - Unpause (CVE-2020-11978)2022-02-01
Suricata
ET EXPLOIT Possible Apache Airflow DAG Example RCE Attempt - Create DAG (CVE-2020-11978)2022-02-01

📋Vendor Advisories

1
CISA
Apache Airflow Command Injection2022-01-18
CVE-2020-11978 — OS Command Injection in Apache Airflow | cvebase