Skip to content
COOEY

EXPOSURES › CVE-2020-11978

CVE-2020-11978

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-11978 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatchedsupply-chain

Apache Airflow shipped with an example DAG containing a remote command injection vulnerability that was actively exploited in the wild.

The vulnerability existed in example code shipped with the software, meaning any user installing Airflow was exposed to remote code execution without needing to patch the core product. DIB organizations must ensure their open-source dependencies are rigorously vetted, as even example code can serve as an attack vector. This failure highlights the risk of shipping unvetted code and the necessity of continuous dependency scanning.

Shame score — Shipping exploitable code in the default installation, which was actively exploited in the wild, demonstrates severe negligence and a failure to vet even example components.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.