An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2020-07-16T23:21:18.000Z

Updated: 2024-08-04T11:48:57.081Z

Reserved: 2020-04-21T00:00:00.000Z

Link: CVE-2020-11981

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-17T00:15:10.400

Modified: 2024-11-21T04:59:02.573

Link: CVE-2020-11981

cve-icon Redhat

No data.