The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking.
References
Link | Resource |
---|---|
https://lists.apache.org/thread.html/b549c7573b342a6e457e5a3225c33054244343927bbfb2a4cdc4cf73@%3Cdev.airflow.apache.org%3E | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2019-01-23 09:29
Updated : 2019-02-20 09:47
NVD link : CVE-2018-20245
Mitre link : CVE-2018-20245
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
apache
- airflow