Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2022-08-16T14:10:09

Updated: 2024-08-03T10:54:03.738Z

Reserved: 2022-08-15T00:00:00

Link: CVE-2022-38362

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-08-16T14:15:08.310

Modified: 2022-08-17T12:20:46.163

Link: CVE-2022-38362

cve-icon Redhat

No data.