Skip to content
Apache AirflowGHSA-976r-qfjj-c24w

Command injection via Celery broker in Apache Airflow

Critical9.8CVE-2020-11981 · Published Jul 27, 2020 · updated Sep 11, 2024

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.11rc11.10.11rc1
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow logs passwords in plaintext
Low2.8Dec 17, 2020
Stored XSS in Apache Airflow
Medium6.1Jul 27, 2020
Insecure default config of Celery worker in Apache Airflow
Critical9.8Jul 27, 2020
Remote code execution (RCE) in Apache Airflow
High8.8Jul 27, 2020
Multiple stored XSS in RBAC Admin screens in Apache Airflow
Medium5.4Jul 27, 2020
XSS in Apache Airflow
Medium4.8May 6, 2020

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.