Apache Airflow Airflow >=2.0.0 and <2.1.3 does not protect the variable import endpoint which allows unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution.
View the template here CVE-2021-38540.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2021-38540