Apache Apache Airflow Git provider是美国Apache基金会的一个工作流调度系统的Git集成组件。 Apache Airflow Git provider 0.4.1之前版本存在加密问题漏洞,该漏洞源于默认禁用SSH主机密钥验证,可能导致攻击者拦截Airflow worker与Git服务器之间的网络路径,实施中间人攻击,捕获SSH部署密钥或注入恶意仓库内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Airflow Git provider | < 0.4.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow Git provider | 0 ~ 0.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59245 | Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-D | |
| CVE-2026-41041 | Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST c | |
| CVE-2026-49876 | Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP reque |
No comments yet