CVE-2022-40189 is a critical OS Command Injection vulnerability affecting Apache Airflow Pig Provider versions prior to 4.0.0, and Apache Airflow installations with the vulnerable provider. An unauthenticated attacker can exploit this to execute arbitrary commands within the task execution context, even without write access to DAG files. With a CVSS score of 9.8 (Critical), this vulnerability allows for complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is currently available and there is minimal community discussion or media coverage, the high EPSS score suggests a non-trivial probability of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.0CPE matchmatch criteria | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* | ||
< 4.0.0CPE matchmatch criteria | cpe:2.3:a:apache:apache-airflow-providers-apache-pig:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.