CVE Vulnerabilities

CVE-2022-38362

Published: Aug 16, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Apache Airflow Dockers Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.

Affected Software

NameVendorStart VersionEnd Version
Apache-airflow-providers-dockerApache*3.0.0 (excluding)

References