CVE-2022-41131
Last modified
CVE-2022-41131 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files. This issue affects Hive Provider versions prior to 4.1.0. EPSS estimates a 1.75% chance of exploitation in the next 30 days.
Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files. This issue affects Hive Provider versions prior to 4.1.0. It also impacts any Apache Airflow versions prior to 2.3.0 in case HIve Provider is installed (Hive Provider 4.1.0 can only be installed for Airflow 2.3.0+). Note that you need to manually install the HIve Provider version 4.1.0 in order to get rid of the vulnerability on top of Airflow 2.3.0+ version that has lower version of the Hive Provider installed).
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Airflow | < 2.3.0 |
| Apache | Apache-Airflow-Providers-Apache-Hive | < 4.1.0 |
References
- https://github.com/apache/airflow/pull/27647Patch, Third Party Advisory
- https://lists.apache.org/thread/wwo3qp0z8gv54yzn7hr04wy4n8gb0vhlIssue Tracking, Mailing List, Third Party Advisory
- https://github.com/apache/airflow/pull/27647Patch, Third Party Advisory
- https://lists.apache.org/thread/wwo3qp0z8gv54yzn7hr04wy4n8gb0vhlIssue Tracking, Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-41131?
How severe is CVE-2022-41131?
How do I fix CVE-2022-41131?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-41121Windows Graphics Component Elevation of Privilege Vulnerabil…7.8
- CVE-2022-41122Microsoft SharePoint Server Spoofing Vulnerability6.5
- CVE-2022-41123Microsoft Exchange Server Elevation of Privilege Vulnerabili…7.8
- CVE-2022-41125Windows CNG Key Isolation Service Elevation of Privilege Vul…7.8
- CVE-2022-41127Microsoft Dynamics NAV and Microsoft Dynamics 365 Business C…8.5
- CVE-2022-41128Windows Scripting Languages Remote Code Execution Vulnerabil…8.8
- CVE-2022-41132Unauthenticated Plugin Settings Change Leading To Stored XSS…6.1
- CVE-2022-41133The affected product DIAEnergie (versions prior to v1.9.01.0…8.8
- CVE-2022-41134Cross-Site Request Forgery (CSRF) in OptinlyHQ Optinly – Exi…8.8
- CVE-2022-41135Unauth. Plugin Settings Change vulnerability in Modula plugi…5.3
- CVE-2022-41136Cross-Site Request Forgery (CSRF) vulnerability leading to S…8.8
- CVE-2022-41137Apache Hive Metastore (HMS) uses SerializationUtilities#dese…8.3
Are you affected by CVE-2022-41131?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
