apache-airflow is a platform to programmatically author, schedule, and monitor workflows.
Affected versions of this package are vulnerable to Remote Code Execution (RCE). The vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). The vulnerability has no impact if examples are disabled by setting
load_examples=False in the config.
apache-airflow to version 1.10.11 or higher.