CVE-2020-11981 PUBLISHED

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.

EPSS 91.59% · 99.7th percentile

Risk Scores

EPSS Score
91.59%
99.7th percentile

Affected Products

VendorProductVersions
Bitnamiairflow0
Bitnamiairflow0, 0, 0

Timeline

References

Open in Interactive Console →