Critical severity9.8NVD Advisory· Published Jul 17, 2020· Updated Jun 17, 2026
CVE-2020-11982
CVE-2020-11982
Description
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and thus remote code execution) on the Worker.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflowPyPI | < 1.10.11 | 1.10.11 |
Affected products
4- osv-coords2 versions
< 1.10.11+ 1 more
- (no CPE)range: < 1.10.11
- (no CPE)range: < 1.10.11
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-9g2w-5f3v-mfmmghsaADVISORY
- lists.apache.org/thread.html/r7255cf0be3566f23a768e2a04b40fb09e52fcd1872695428ba9afe91%40%3Cusers.airflow.apache.org%3EnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-11982ghsaADVISORY
- github.com/apache/airflow/pull/13612ghsaWEB
- github.com/apache/airflow/pull/7205ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2020-16.yamlghsaWEB
News mentions
0No linked articles in our index yet.