First published: Wed Jan 23 2019(Updated: )
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Airflow | <=1.8.2 | |
pip/apache-airflow | <=1.8.2 | 1.9.0 |
<=1.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17835 is classified as a critical vulnerability due to its potential for remote command injection.
To fix CVE-2017-17835, upgrade Apache Airflow to version 1.9.0 or later.
Apache Airflow versions 1.8.2 and earlier are affected by CVE-2017-17835.
CVE-2017-17835 is a Cross-Site Request Forgery (CSRF) vulnerability.
Yes, CVE-2017-17835 can be exploited remotely, allowing attackers to perform command injection.