CVE-2020-11981

CRITICAL9.8EPSS 91.6%

Command injection via Celery broker in Apache Airflow

發布日:2020/7/27修改日:2025/4/3
也稱為:GHSA-976r-qfjj-c24wBIT-airflow-2020-11981PYSEC-2020-15

描述

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(8)