Description:Apache Airflow Docker's Provider shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.
Mitigation:Disable loading of example DAGs or upgrade the apache-airflow-providers-docker to 3.0.0 or above
Credit: Thanks to Kai Zhao of 3H Secruity Team for reporting this