QID 980748

QID 980748: Python (pip) Security Update for apache-airflow (GHSA-rvmq-4x66-q7j3)

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are advised to refer to GHSA-rvmq-4x66-q7j3 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980748

    Software Advisories
    Advisory ID Software Component Link
    GHSA-rvmq-4x66-q7j3 apache-airflow URL Logo github.com/advisories/GHSA-rvmq-4x66-q7j3