EXPOSURES › CVE-2020-11978
CVE-2020-11978
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Airflow shipped with an example DAG containing a remote command injection vulnerability that was actively exploited in the wild.
The vulnerability existed in example code shipped with the software, meaning any user installing Airflow was exposed to remote code execution without needing to patch the core product. DIB organizations must ensure their open-source dependencies are rigorously vetted, as even example code can serve as an attack vector. This failure highlights the risk of shipping unvetted code and the necessity of continuous dependency scanning.
Shame score — Shipping exploitable code in the default installation, which was actively exploited in the wild, demonstrates severe negligence and a failure to vet even example components.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.