← back
CVE-2020-11982

CVE-2020-11982

EPSS 7.2%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 7.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
16 Jul 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and thus remote code execution) on the Worker.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →