PT-2019-10037 · Apache · Apache Airflow

Publicado

2019-01-23

·

Atualizado

2019-02-20

·

CVE-2018-20245

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Apache Airflow versions prior to 1.10.1
Description: The LDAP auth backend in Apache Airflow was misconfigured, containing improper checking of exceptions which disabled server certificate checking.
Recommendations: For versions prior to 1.10.1, update to Apache Airflow version 1.10.1 or later to resolve the issue.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-20245
GHSA-77RC-X84Q-PV4F
PYSEC-2019-143

Produtos afetados

Apache Airflow