CVE Published: 20/02/2024 |
CVE Updated: 15/08/2024 |
CVE Year: 2024 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Airflow Mongo Provider Status : PUBLISHED
CVE-2024-25141 Description
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented.
Users are recommended to upgrade to version 4.0.0, which fixes this issue.