Executive brief
A remote command injection vulnerability exists in an example DAG shipped with Apache Airflow versions 1.10.10 and below. Authenticated users can execute arbitrary commands as the user running the Airflow worker or scheduler. The vulnerability is only present if example DAGs are enabled (load_examples=True).
Affected products
- Apache Airflow <= 1.10.10
Timeline
- 2020-07-16: disclosed: NVD Published Date
- 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog