Mongo Hook Fixes Unexpected SSL Validation Issue
CVE-2024-25141
Currently unrated
Key Information:
- Vendor
- Apache
- Vendor
- CVE Published:
- 20 February 2024
Summary
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.
Affected Version(s)
Apache Airflow Mongo Provider 1.0.0 < 4.0.0
References
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Noah Stapp