PT-2026-52668 · Apache · Apache Airflow Ftp Provider
Andrew Rukin
+1
·
Publicado
2026-06-26
·
Atualizado
2026-06-26
·
CVE-2026-49486
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
The Apache Airflow FTP provider's
FTPSHook.get conn() created an ftplib.FTP TLS connection but never called prot p(), so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using FTPSHook or FTPSFileTransmitOperator to move files over FTPS exposed file contents and credentials-in-transit to a network attacker able to observe the data connection. Upgrade apache-airflow-providers-ftp to 3.15.1 or later, which issues PROT P to encrypt the data channel.Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Airflow Ftp Provider