CNNVD-202507-3368 Information
CNNVD ID
CNNVD-202507-3368
Related CVE
- CNNVD Published: 2025-07-26
Description (Chinese)
dag-factory是Astronomer开源的一个通过构建Apache Airflow DAG的软件。 dag-factory 0.23.0a8及之前版本存在操作系统命令注入漏洞,该漏洞源于cicd.yml工作流配置不当,可能导致任意代码执行。
Description (English)
Dag-factory is a software from the Astronomer open source that builds Apache AirFlow DAG. Dag-factory 0.23.0a8 and previous versions had an operational system command-infusion loop, which stemmed from the inappropriate configuration of cicd.yml workflow, which could lead to arbitrary code enforcement.
Hazard Level
Low
Vulnerability Type
操作系统命令注入
Affected Vendor
Astronomer
Published
2025-07-26
Last Modified
2026-02-24
References
https://github.com/astronomer/dag-factory/pull/460 https://github.com/astronomer/dag-factory/security/advisories/GHSA-g5hx-xv45-9whg https://github.com/astronomer/dag-factory/commit/751c0e58369e784f6a924347e381a705ea8133fe https://github.com/astronomer/dag-factory/pull/466 https://access.redhat.com/security/cve/cve-2025-54415
Patch
https://github.com/astronomer/dag-factory/releases
Share on: