CVE Vulnerabilities

CVE-2022-38362

Published: Aug 16, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Apache Airflow Dockers Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.

Affected Software

Name Vendor Start Version End Version
Apache-airflow-providers-docker Apache * 3.0.0 (excluding)

References