Publish GHSA-rvmq-4x66-q7j3

This commit is contained in:
advisory-database[bot]
2024-07-25 14:04:31 +00:00
parent 9ba57951d2
commit 2dc5c3ebe5
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvmq-4x66-q7j3",
"modified": "2024-03-25T14:24:36Z",
"modified": "2024-07-25T14:03:04Z",
"published": "2020-07-27T16:57:33Z",
"aliases": [
"CVE-2020-11978"
],
"summary": "Remote code execution in Apache Airflow",
"summary": "Remote code execution (RCE) in Apache Airflow",
"details": "An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.",
"severity": [
{