CVE-2020-11978: Apache Airflow Command Injection
A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. Required action: Apply updates per vendor instructions.
CISA KEV ↗ · unattributed attribution