Critical severityNVD Advisory· Published Feb 20, 2024· Updated Feb 13, 2025
Apache Airflow Mongo Provider: Certificate validation isn't respected even if SSL is enabled for apache-airflow-providers-mongo
CVE-2024-25141
Description
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflow-providers-mongoPyPI | < 4.0.0 | 4.0.0 |
Affected products
2- Range: 1.0.0
Patches
Vulnerability mechanics
References
5- github.com/apache/airflow/pull/37214ghsapatchWEB
- github.com/advisories/GHSA-x5pm-h33q-cjrwghsaADVISORY
- lists.apache.org/thread/sqgbfqngjmn45ommmrgj7hvs7fgspsgmghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-25141ghsaADVISORY
- www.openwall.com/lists/oss-security/2024/02/20/5ghsaWEB
News mentions
0No linked articles in our index yet.