Apache AirflowGHSA-3v7g-4pg3-7r6j
OS Command injection in Apache Airflow
High8.8CVE-2022-24288 · Published Feb 26, 2022 · updated Sep 12, 2024
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.2.4 | 2.2.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-78
- Also known as
- BIT-airflow-2022-24288, CVE-2022-24288, PYSEC-2022-30
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 32022 | Apache Airflow exposes arbitrary file content | Medium4.7 | 2.3.4 |
| May 242022 | Missing Authentication for Critical Function in Apache Airflow | Critical9.8 | 2.1.3 |
| May 142022 | Apache Airflow Reflected Cross-site Scripting vulnerability in 404 Endpoint | Medium6.1 | 1.9.0 |
| Feb 262022 | Apache Airflow Cross-site Scripting Vulnerability | Medium6.1 | 2.2.4rc1 |
| Jan 282022 | Improper Privilege Management in apache-airflow | Medium6.5 | 2.2.0 |
| Aug 302021 | Missing Authorization in Apache Airflow | Medium5.3 | 2.1.2 |