Loading HuntDB...

GHSA-x5pm-h33q-cjrw

GitHub Security Advisory

Improper Certificate Validation in apache airflow mongo hook

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented.
Users are recommended to upgrade to version 4.0.0, which fixes this issue.

Affected Packages

PyPI apache-airflow-providers-mongo
Affected versions: 0 (fixed in 4.0.0)

Related CVEs

Key Information

GHSA ID
GHSA-x5pm-h33q-cjrw
Published
February 20, 2024 9:30 PM
Last Modified
August 15, 2024 9:37 PM
CVSS Score
9.0 /10
Primary Ecosystem
PyPI
Primary Package
apache-airflow-providers-mongo
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 12, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.