{"id":"CVE-2022-24288","summary":"Apache Airflow: RCE in example DAGs","details":"In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.","aliases":["BIT-airflow-2022-24288","GHSA-3v7g-4pg3-7r6j","PYSEC-2022-30"],"modified":"2026-08-12T03:51:34.283846505Z","published":"2022-02-25T08:30:16Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"2.2.4"}]}],"cna_assigner":"apache","cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24288.json"},"references":[{"type":"WEB","url":"https://lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23t"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24288.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24288"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/airflow","events":[{"introduced":"0"},{"fixed":"be4330b578012a13bbfdcce7e04768ad13b7f08f"}],"database_specific":{"cpe":"cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.2.4"}],"source":"CPE_RANGE"}}],"versions":["constraints-2.2.4rc1","constraints-2.2.1rc2","constraints-2.2.1rc1","constraints-2.2.3rc2","constraints-2.2.3rc1","constraints-2.2.2rc2","constraints-2.2.2rc1","constraints-2.2.0rc1","constraints-2.2.0b2","constraints-2.2.0b1","constraints-2.1.0rc1","constraints-2.0.1rc1","constraints-2.0.0rc3","constraints-2.0.0rc2","constraints-2.0.0rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24288.json"}}],"schema_version":"1.9.0"}