Skip to content
Apache AirflowGHSA-9g2w-5f3v-mfmm

Insecure default config of Celery worker in Apache Airflow

Critical9.8CVE-2020-11982 · Published Jul 27, 2020 · updated Sep 11, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.111.10.11
Details and references

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and thus remote code execution) on the Worker.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
BIT-airflow-2020-11982, CVE-2020-11982, PYSEC-2020-16

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Jul 272020Multiple stored XSS in RBAC Admin screens in Apache Airflow
CVE-2020-11983Medium5.4fixed in 1.10.11
Jul 272020Command injection via Celery broker in Apache Airflow
CVE-2020-11981Critical9.8fixed in 1.10.11rc1
Jul 272020Remote code execution (RCE) in Apache Airflow
CVE-2020-11978High8.8fixed in 1.10.11rc1
Jul 272020Stored XSS in Apache Airflow
CVE-2020-9485Medium6.1fixed in 1.10.11
May 62020XSS in Apache Airflow
CVE-2019-12398Medium4.8fixed in 1.10.5
Dec 172020Apache Airflow logs passwords in plaintext
CVE-2020-17511Low2.8fixed in 1.10.13

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.