Apache Airflow 系统命令注入(CVE-2022-24288)

2022-04-11 Apache Airflow PoC No

Description

Apache 2.2.4版之前的版本容易受到OS命令注入攻击,因为一些示例DAG没有正确清理用户提供的参数,使它们容易受到来自web UI的OS命令注入的影响。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities