Apache Airflow
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*
- >= 3.1.8, < 3.2.0
A vulnerability exists in Apache Airflow versions 3.1.8 prior to 3.2.0, allowing Dag Authors to execute arbitrary code in the webserver context by crafting XCom payloads. This issue arises from an unsafe deserialization via legacy serialization keys, which Dag Authors, despite their trusted status, should not be able to exploit.
Exploitation of this vulnerability could lead to unauthorized code execution on the webserver.
Users are advised to upgrade to Apache Airflow 3.2.0, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.