michalc opened a new issue #16541:
URL: https://github.com/apache/airflow/issues/16541


   **Description**
   
   flask-caching has a published vulnerability 
https://nvd.nist.gov/vuln/detail/CVE-2021-33026#vulnCurrentDescriptionTitle 
where access to the cache store would lead to authorised code execution in 
Superset. Unfortunately, a fix does not appear available at this time.
   
   **Use case / motivation**
   
   Would like to run Airflow without known vulnrabilities
   
   **Are you willing to submit a PR?**
   
   No...
   
   **Related Issues**
   
   https://github.com/sh4nks/flask-caching/pull/209
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
[email protected]


Reply via email to