CVE-2020-11982 PUBLISHED

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and thus remote code execution) on the Worker.

EPSS 5.66% · 90.3th percentile

Risk Scores

EPSS Score
5.66%
90.3th percentile

Affected Products

VendorProductVersions
Bitnamiairflow0
Bitnamiairflow0, 0, 0

Timeline

References

Open in Interactive Console →