CVE-2022-24288

In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
CVSS

No CVSS.

Configurations

No configuration.

Information

Published : 2022-02-25 09:15

Updated : 2022-02-25 12:57


NVD link : CVE-2022-24288

Mitre link : CVE-2022-24288


JSON object : View

Products Affected

No product.

CWE

No CWE.