Apache Airflow Providers Edge3 RCE Vulnerability
An early warning has been issued regarding a potential remote code execution vulnerability in the Apache Airflow Providers Edge3 package. This issue appears to affect versions before 2.0.0 when used with Airflow 2.
What happened
According to the GitHub Advisory Database, the Apache Airflow Providers Edge3 package may expose an internal API that allows remote code execution in the web server context. This vulnerability is under investigation and reportedly affects versions before 2.0.0 when used with Airflow 2. To assess your exposure, check if your environment includes apache-airflow-providers-edge3 version less than 2.0.0 and is integrated with Airflow 2.
As a precautionary measure, it is recommended to uninstall apache-airflow-providers-edge3 and migrate to Airflow 3. Additionally, ensure that you upgrade to version 2.0.0 or higher of apache-airflow-providers-edge3 if migration is not immediately feasible. For more detailed information, consult the primary sources linked in the advisory.
How 0Day mitigates this
apache-airflow-providers-edge3 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.