{"id":"CVE-2022-24288","aliases":["BIT-airflow-2022-24288","GHSA-3v7g-4pg3-7r6j","PYSEC-2022-30"],"url":"https://o3.security/vulnerability/CVE-2022-24288","summary":"Apache Airflow: RCE in example DAGs","details":"In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.","published":"2022-02-25T08:30:16Z","modified":"2026-08-12T03:51:34.283846505Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"apache-airflow","fixedVersion":"2.2.4"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23t"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24288.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24288"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:34.283846505Z"}}