← Back to CVE List

CVE-2020-11981

Published: 2020-07-17T00:15Z
Last Modified: 2024-11-21T04:59Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt