CVE-2024-25141

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
20/02/2024
Last modified:
28/04/2025

Description

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented.<br /> Users are recommended to upgrade to version 4.0.0, which fixes this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:apache-airflow-providers-mongo:*:*:*:*:*:*:*:* 1.0.0 (including) 4.0.0 (excluding)