CVE-2024-25141

apache/airflow
on github

Published

Severity

CVSS v3:
N/A
CVSS v2:
N/A

Description

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.

References

Configurations

CPE23Version StartVersion EndExact Version

External Links