Apache Airflow Dockers Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Apache-airflow-providers-docker |
Apache |
* |
3.0.0 (excluding) |
References