Executive brief
Apache Airflow's Experimental API was configured by default to allow all requests without authentication. This insecure default initialization allows unauthenticated remote attackers to perform critical functions, potentially leading to remote code execution.
Affected products
- Apache Airflow versions up to 1.10.10
Timeline
- 2020-11-24: disclosed: Initial analysis by NIST
- 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-18: advisory: NVD publication date