CVE-2022-38362

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/08/2022
Last modified:
17/08/2022

Description

Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:apache-airflow-providers-docker:*:*:*:*:*:*:*:* 3.0.0 (excluding)