CVE-2024-25141

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-25141
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-25141.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-25141
Aliases
Published
2024-02-20T21:15:08Z
Modified
2025-05-01T00:12:10.551613Z
Summary
[none]
Details

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.

References

Affected packages

Git / github.com/apache/airflow

Affected ranges

Type
GIT
Repo
https://github.com/apache/airflow
Events