CVE-2022-38362
published 2022-08-16CVE-2022-38362: Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow…
PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.60%
73.0th percentile
Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache-airflow-providers-docker | < 3.0.0 | 3.0.0 |
| apache | apache-airflow-providers-docker | >= 0 < 3.0.0 | 3.0.0 |
| apache_software_foundation | apache_airflow | >= Apache Airflow Docker Provider < 3.0.0 | 3.0.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Remote code execution in Apache Airflow Docker's Provider
osv·2022-08-17
CVE-2022-38362 [HIGH] Remote code execution in Apache Airflow Docker's Provider
Remote code execution in Apache Airflow Docker's Provider
Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host. Disable loading of example DAGs or upgrade apache-airflow-providers-docker to 3.0.0 or above.
GHSA
Remote code execution in Apache Airflow Docker's Provider
ghsa·2022-08-17
CVE-2022-38362 [HIGH] Remote code execution in Apache Airflow Docker's Provider
Remote code execution in Apache Airflow Docker's Provider
Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host. Disable loading of example DAGs or upgrade apache-airflow-providers-docker to 3.0.0 or above.
No detection rules found.
No public exploits indexed.
2022-08-16
Published