High severity8.8NVD Advisory· Published Feb 25, 2022· Updated Jun 17, 2026
CVE-2022-24288
CVE-2022-24288
Description
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflowPyPI | < 2.2.4 | 2.2.4 |
Affected products
4- osv-coords2 versions
< 2.2.4+ 1 more
- (no CPE)range: < 2.2.4
- (no CPE)range: < 2.2.4
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-3v7g-4pg3-7r6jghsaADVISORY
- lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23tnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-24288ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2022-30.yamlghsaWEB
News mentions
0No linked articles in our index yet.