CNNVD-202507-3368 Information

CNNVD ID

CNNVD-202507-3368

CVE-2025-54415

  • CNNVD Published: 2025-07-26

Description (Chinese)

dag-factory是Astronomer开源的一个通过构建Apache Airflow DAG的软件。 dag-factory 0.23.0a8及之前版本存在操作系统命令注入漏洞,该漏洞源于cicd.yml工作流配置不当,可能导致任意代码执行。

Description (English)

Dag-factory is a software from the Astronomer open source that builds Apache AirFlow DAG. Dag-factory 0.23.0a8 and previous versions had an operational system command-infusion loop, which stemmed from the inappropriate configuration of cicd.yml workflow, which could lead to arbitrary code enforcement.

Hazard Level

Low

Vulnerability Type

操作系统命令注入

Affected Vendor

Astronomer

Published

2025-07-26

Last Modified

2026-02-24

References

https://github.com/astronomer/dag-factory/pull/460 https://github.com/astronomer/dag-factory/security/advisories/GHSA-g5hx-xv45-9whg https://github.com/astronomer/dag-factory/commit/751c0e58369e784f6a924347e381a705ea8133fe https://github.com/astronomer/dag-factory/pull/466 https://access.redhat.com/security/cve/cve-2025-54415

Patch

https://github.com/astronomer/dag-factory/releases

Share on: