SOURCE FACT
Apache · Airflow
A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.
Required action
Apply updates per vendor instructions.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2020-11978
View source evidence →