3.1.2
7 months ago
1 days ago
Known vulnerabilities in the apache-airflow-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Command Injection via the Note: This is only exploitable if example DAGs are enabled in production or if the example DAG code is copied to create a similar DAG. How to fix Command Injection? Upgrade | [3.0.0,3.0.5) |
Affected versions of this package are vulnerable to Execution with Unnecessary Privileges via the How to fix Execution with Unnecessary Privileges? Upgrade | [3.0.0,3.1.1) |
Affected versions of this package are vulnerable to Execution with Unnecessary Privileges via the Note: This is only exploitable if the API server is deployed in an environment where DAG files are accessible to the server. How to fix Execution with Unnecessary Privileges? Upgrade | [3.0.0,3.1.1) |