← Back to browse · API

CVE-2022-40127

Severity
HIGH
CVSS
8.8
EPSS
0.85653
Risk score
65.18
CISA KEV
No
PoC
No
Published
2022-11-14
Modified
2025-04-30
First seen
2026-08-07
Aliases
EUVD-2022-0017, GHSA-6PW3-8H9W-32GC, PYSEC-2022-42982
Products
Apache Software Foundation:Apache Airflow Apache Airflow <2.4.0
Sources
euvd EUVD-2022-0017

Description

A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.

References