CVE-2022-40127

CVE-2022-40127: Apache Airflow <2.4.0 has an RCE in a bash example

Vendor Apache Software Foundation
Product Apache Airflow
Weakness CWE-94 · Code injection
Published November 14, 2022
Last update April 30, 2025

CVSS base score

What the vulnerability does

Description

A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.

Key dates

Disclosure timeline

November 14, 2022 CVE published
April 30, 2025 Record updated