NA

CVE-2024-25141

Published: 20/02/2024 Updated: 20/02/2024

Vulnerability Summary

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.

Mailing Lists

Severity: low Affected versions: - Apache Airflow Mongo Provider 100 before 400 Description: When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated This was unexpected and undocumented Users are recommended to upgrade to version 400, which fixes this issue ...