Loading HuntDB...

GHSA-3gg8-mc87-cq3h

GitHub Security Advisory

Improper Certificate Validation vulnerability in Apache Airflow FTP Provider

✓ GitHub Reviewed LOW Has CVE

Advisory Details

Improper Certificate Validation vulnerability in Apache Airflow FTP Provider.

The FTP hook lacks complete certificate validation in FTP_TLS connections, which can potentially be leveraged. Implementing proper certificate validation by passing context=ssl.create_default_context() during FTP_TLS instantiation is used as mitigation to validate the certificates properly.

This issue affects Apache Airflow FTP Provider: before 3.7.0.

Users are recommended to upgrade to version 3.7.0, which fixes the issue.

Affected Packages

PyPI apache-airflow-providers-ftp
Affected versions: 0 (fixed in 3.7.0)

Related CVEs

Key Information

GHSA ID
GHSA-3gg8-mc87-cq3h
Published
April 21, 2024 6:30 PM
Last Modified
July 3, 2024 8:40 PM
CVSS Score
2.5 /10
Primary Ecosystem
PyPI
Primary Package
apache-airflow-providers-ftp
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.