CVE-2022-38362 Information

Description

Apache Airflow Docker’s Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.

Reference

https://lists.apache.org/thread/614p38nf4gbk8xhvnskj9b1sqo2dknkb http://www.openwall.com/lists/oss-security/2022/08/16/1

Share on: