Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-6497 Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.
Github GHSA Github GHSA GHSA-746v-hfh2-xphm Remote code execution in Apache Airflow Docker's Provider
Fixes

Solution

No solution given by the vendor.


Workaround

Disable loading of example DAGs or upgrade the apache-airflow-providers-docker to 3.0.0 or above

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T10:54:03.738Z

Reserved: 2022-08-15T00:00:00

Link: CVE-2022-38362

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-16T14:15:08.310

Modified: 2024-11-21T07:16:19.723

Link: CVE-2022-38362

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.