Apache Airflow Dockers Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Apache-airflow-providers-docker | Apache | * | 3.0.0 (excluding) |
References