PromptRiskDBThreat intelligence atlas

CVE-2020-11978 - Apache Airflow

AI Vulnerability Context

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are...

Overview

A source-backed snapshot of this vulnerability.

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVHIGH
CVE ID
CVE-2020-11978
Vendor/project
Apache
Product
Airflow
Vulnerability name
Apache Airflow Command Injection
Date added
2022-01-18
Due date
2022-07-18
Known ransomware campaign use
Unknown
CVSS v3
8.8
CWE-78

Exploit context

What the vulnerability is about.

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.