In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
Created golang-cloud-google tracking bugs for this issue: Affects: fedora-all [bug 2058383] Created golang-google-genproto tracking bugs for this issue: Affects: fedora-all [bug 2058384]
References: https://lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23t
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.