CVE-2022-38362
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.
Affected (1)
Products: Apache: Apache Airflow Providers Docker
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.0 |
References (4)
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Timeline
No history available yet.