peter bassill · operator
$ cve CVE-2020-11982 JSON

CVE-2020-11982

9.8
CRITICAL · CVSS 3.1 · EPSS 7.2% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and thus remote code execution) on the Worker.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.23% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2020-07-17
Last modified2026-06-17

Affected (1)

VendorProduct
apacheairflow

References

→ the Explorer  ·  watch your stack  ·  NVD