Junglewise Threat Intelligence

CVE-2020-11978: PYSEC-2020-14 - An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the

CVE-2020-11978 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2020-07-17

Technologies: Apache Airflow, apache-airflow (PyPI). Vendors: Apache, PyPI.

Executive brief

A remote command injection vulnerability exists in an example DAG shipped with Apache Airflow versions 1.10.10 and below. Authenticated users can execute arbitrary commands as the user running the Airflow worker or scheduler. The vulnerability is only present if example DAGs are enabled (load_examples=True).

Affected products

  • Apache Airflow <= 1.10.10

Timeline

  • 2020-07-16: disclosed: NVD Published Date
  • 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats