QID 980746
QID 980746: Python (pip) Security Update for apache-airflow (GHSA-9g2w-5f3v-mfmm)
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and thus remote code execution) on the Worker.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9g2w-5f3v-mfmm for updates pertaining to this vulnerability.
Vendor References
- GHSA-9g2w-5f3v-mfmm -
github.com/advisories/GHSA-9g2w-5f3v-mfmm
CVEs related to QID 980746
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9g2w-5f3v-mfmm | apache-airflow |
|