S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-11978 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Apache Airflow affects v. 1.10.10 and below.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-11978
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Apache Airflowby Apache Software Foundation
1.10.10 and below
Updated Aug 21, 2026View on NVD →
Detail

Apache Airflow is an open-source platform that is used to programmatically author, schedule, and monitor workflows as directed acyclic graphs (DAGs). It is commonly used by data engineers and scientists to automate the processing of their data pipelines. The software provides a way to manage these workflows through its user interface, or its APIs.

The CVE-2020-11978 vulnerability is a remote code/command injection issue that was discovered in Apache Airflow versions 1.10.10 and below. This security flaw exists within one of the example DAGs that are shipped with Apache Airflow. An authenticated user can execute arbitrary commands as the user running the airflow worker/scheduler, depending on the executor in use. 

Exploitation of this vulnerability can lead to unauthorized access to sensitive information and also take over the affected system. Attackers can take over the Apache Airflow system and use it to execute malicious scripts, install malware, and even perform data sabotage. Considering the importance of the data being processed by Apache Airflow workflows, this can lead to significant damage to an organization's operations.

s4e.io offers a platform that caters to staying up-to-date with cybersecurity news and alerts, identifying and prioritizing vulnerabilities, and automating assessments to prevent potential threats. By utilizing the professional features of s4e.io, companies can easily identify and combat vulnerabilities within their digital assets. The platform provides a hassle-free solution to safeguarding against unforeseeable cyber threats, allowing organizations to focus on their core activities instead of worrying about cybersecurity risks.

 

REFERENCES

Solution Advice

Precautions can be taken to protect against this vulnerability by implementing the following measures:

  • Update to the latest version of Apache Airflow
  • Disable all example DAGs by setting load_examples=False in the configuration
  • Restrict access to Apache Airflow systems to only authorized personnel
  • Implement network segmentation to isolate Apache Airflow from public networks
  • Implement additional security measures, such as firewalls and intrusion detection systems

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-11978 scanner - Remote Code Execution (RCE) vulnerability in Apache Airflow | S4E