ZeroHour

CVE-2022-38362

CVSS 3.1
8.8 high
EPSS
2%p78
Published
()
Modified
Description

Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.

Vendors
apache
Products
apache-airflow-providers-docker
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.