Описание
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.
Ссылки
- Mailing List
- Issue TrackingPatch
- Mailing List
- Mailing List
- Issue TrackingPatch
- Mailing List
Уязвимые конфигурации
Конфигурация 1Версия от 1.0.0 (включая) до 4.0.0 (исключая)
cpe:2.3:a:apache:apache-airflow-providers-mongo:*:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00097
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-295
CWE-295
Связанные уязвимости
CVSS3: 9.1
github
почти 2 года назад
Improper Certificate Validation in apache airflow mongo hook
EPSS
Процентиль: 27%
0.00097
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-295
CWE-295