Back to search
CVE-2022-38362
Published: Aug 16, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Airflow | affected Apache Airflow Docker Provider - < 3.0.0 |
References
https://lists.apache.org/thread/614p38nf4gbk8xhvnskj9b1sqo2dknkb
x_refsource_MISC
[oss-security] 20220816 CVE-2022-38362: Apache Airflow Docker Provider <3.0 RCE vulnerability in example dag
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now