Description
Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.
No analysis available yet.
Remediation
Vendor Workaround
Disable loading of example DAGs or upgrade the apache-airflow-providers-docker to 3.0.0 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6497 | Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host. |
Github GHSA |
GHSA-746v-hfh2-xphm | Remote code execution in Apache Airflow Docker's Provider |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T10:54:03.738Z
Reserved: 2022-08-15T00:00:00.000Z
Link: CVE-2022-38362
No data.
Status : Modified
Published: 2022-08-16T14:15:08.310
Modified: 2024-11-21T07:16:19.723
Link: CVE-2022-38362
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA