github.com
https://github.com/advisories/GHSA-3v7g-4pg3-7r6j CVE-2022-24288
Nuclei
Apache Airflow: RCE in example DAGs
Record summary
EIP currently links 1 Nuclei template to CVE-2022-24288.
Description
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 8, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
AirflowBrowse Apache / Airflow | VulnCheck | Version data not supplied | |
Apache AirflowBrowse Apache Software Foundation / Apache Airflow | CVE List | Before 2.2.4 | affected |
apache-airflowBrowse PyPI / apache-airflow | GitHub Advisory | Before 2.2.4 · Fixed in 2.2.4 | affected |
Nuclei templates
1ProjectDiscoveryHIGHApache Airflow OS Command InjectionCVSS 8.8
Apache Airflow prior to version 2.2.4 is vulnerable to OS command injection attacks because some example DAGs do not properly sanitize user-provided parameters, making them susceptible to OS Command Injection from the web UI.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the target system.
Remediation
Apply the latest security patches or upgrade to a patched version of Apache Airflow.
WeaknessesCWE-78
Authorsxeldax
Template tagscvecve2022airflowrceapachevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
Shodan: title:"Airflow - DAGs" || http.html:"Apache Airflow"
Shodan: http.title:"airflow - dags" || http.html:"apache airflow"
Shodan: http.title:"sign in - airflow"
Shodan: product:"redis"
FOFA: title="sign in - airflow"
FOFA: apache airflow
FOFA: title="airflow - dags" || http.html:"apache airflow"
Google: intitle:"sign in - airflow"
Google: intitle:"airflow - dags" || http.html:"apache airflow"
https://github.com/advisories/GHSA-3v7g-4pg3-7r6j https://nvd.nist.gov/vuln/detail/CVE-2022-24288 https://lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23t https://github.com/ARPSyndicate/kenzer-templates https://github.com/Hax0rG1rl/my_cve_and_bounty_poc
Source: ProjectDiscovery
References
5github.com
https://github.com/apache/airflow github.com
https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2022-30.yaml lists.apache.org
https://lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23t nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-24288