CVE-2022-24288: Apache Airflow: RCE in example DAGs
Published Feb 25, 2022
·Updated
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
Affected Software
2 affected componentsFixes available
Apache Airflow<2.2.4
pip/apache-airflow<2.2.4
2.2.4
Event History
Feb 25, 2022
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionWeakness
Feb 26, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is CVE-2022-24288?
CVE-2022-24288 is a vulnerability in Apache Airflow prior to version 2.2.4 that allows for OS Command Injection from the web UI.
2
How severe is CVE-2022-24288?
CVE-2022-24288 has a severity score of 8.8, which is considered high.
3
How does CVE-2022-24288 affect Apache Airflow?
CVE-2022-24288 affects Apache Airflow versions prior to 2.2.4.
4
How can I fix CVE-2022-24288?
To fix CVE-2022-24288, update Apache Airflow to version 2.2.4 or later.
5
Where can I find more information about CVE-2022-24288?
More information about CVE-2022-24288 can be found at the following link: [https://lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23t](https://lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23t)