Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x5pm-h33q-cjrw

Опубликовано: 20 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Improper Certificate Validation in apache airflow mongo hook

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.

Пакеты

Наименование

apache-airflow-providers-mongo

pip
Затронутые версииВерсия исправления

< 4.0.0

4.0.0

EPSS

Процентиль: 27%
0.00097
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 9.1
nvd
почти 2 года назад

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.

EPSS

Процентиль: 27%
0.00097
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-295