PyPI package intelligence
apache-airflow Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the PyPI package apache-airflow, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 3
- Known exploited vulnerabilities affecting apache-airflow
- In CISA KEV
- 2
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- apache-airflow KEVs with sensor-observed exploitation activity
Review apache-airflow exploitation against the versions you run
One of the three exploited apache-airflow vulnerabilities tracked here are not in CISA KEV.
- 67%
- Covered by CISA
- 33%
- Beyond CISA
Attested apache-airflow vulnerabilities
3 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2020-13927
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to... |
In CISA | 18 Jan 2022 |
|
CVE-2020-11978
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example... |
In CISA | 18 Jan 2022 |
|
CVE-2022-24288
Apache Airflow: RCE in example DAGs |
Beyond CISA | 25 Feb 2022 |
Recurring weakness patterns
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Invokable Control Element with Variadic Parameters, and Initialization of a Resource with an Insecure Default account for mapped occurrences across this apache-airflow KEV portfolio.