cbcvebase.
CVE-2022-40127
published 2022-11-14

CVE-2022-40127: A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.

Affected

2 ranges
VendorProductVersion rangeFixed in
apacheairflow< 2.4.02.4.0
apache_software_foundationapache_airflow>= Apache Airflow < 2.4.02.4.0