CVE Published: 25/02/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Airflow Status : PUBLISHED
CVE-2022-24288 Description
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
CWE-ID: CWE-78 CWE Name: CWE-78 Improper Neutralization of Special Elements used in an OS Command (
OS Command Injection
) Source: Apache Software Foundation
Common Attack Pattern Enumeration and Classification (CAPEC)