← Back to browse · API

CVE-2020-11978

Severity
HIGH
CVSS
8.8
EPSS
0.99189
Risk score
59.72
CISA KEV
Yes
PoC
No
Published
2020-07-16
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2020-0032, GHSA-RVMQ-4X66-Q7J3, PYSEC-2020-14
Products
Apache Software Foundation:Apache Airflow 1.10.10 and below, Apache:Airflow
Sources
cisa.gov CVE-2020-11978
euvd EUVD-2020-0032

Description

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.

References