Apache Airflow
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*
- < 3.2.0
A vulnerability exists in Apache Airflow in versions prior to 3.2.0, where Dag Authors can craft XCom payloads that trigger the webserver to execute arbitrary code. This issue arises because Dag Authors are considered highly trusted, although the overall severity is rated low.
Exploitation of this vulnerability allows for arbitrary code execution on the webserver.
Users are advised to upgrade to Apache Airflow 3.2.0, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.