Record summary

EIP currently links 1 Nuclei template to CVE-2022-24288.

Description

In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 8, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE ListBefore 2.2.4affected
GitHub AdvisoryBefore 2.2.4 · Fixed in 2.2.4affected

Nuclei templates

1
ProjectDiscoveryHIGHApache Airflow OS Command InjectionCVSS 8.8

Apache Airflow prior to version 2.2.4 is vulnerable to OS command injection attacks because some example DAGs do not properly sanitize user-provided parameters, making them susceptible to OS Command Injection from the web UI.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the target system.

Remediation

Apply the latest security patches or upgrade to a patched version of Apache Airflow.

WeaknessesCWE-78
Authorsxeldax
Template tagscvecve2022airflowrceapachevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
Shodan: title:"Airflow - DAGs" || http.html:"Apache Airflow"
Shodan: http.title:"airflow - dags" || http.html:"apache airflow"
Shodan: http.title:"sign in - airflow"
Shodan: product:"redis"
FOFA: title="sign in - airflow"
FOFA: apache airflow
FOFA: title="airflow - dags" || http.html:"apache airflow"
Google: intitle:"sign in - airflow"
Google: intitle:"airflow - dags" || http.html:"apache airflow"

Source: ProjectDiscovery

References

5