Описание
Apache Airflow's SMTP provider SmtpHook called Python's smtplib.SMTP.starttls() without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between the Airflow worker and the SMTP server could present a self-signed certificate, complete the STARTTLS upgrade, and capture the SMTP credentials sent during the subsequent login() call. Users are advised to upgrade to the apache-airflow-providers-smtp version that contains the fix.
Ссылки
- Issue TrackingPatch
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2.0.0 (включая) до 3.0.0 (исключая)
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
EPSS
Процентиль: 19%
0.00268
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-295
Связанные уязвимости
CVSS3: 5.9
debian
4 месяца назад
Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMT ...
CVSS3: 5.9
github
4 месяца назад
apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider
EPSS
Процентиль: 19%
0.00268
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-295