Improper Certificate Validation in Apache Airflow
High severity
GitHub Reviewed
Published
Jan 25, 2019
to the GitHub Advisory Database
•
Updated Sep 4, 2024
Description
Published to the GitHub Advisory Database
Jan 25, 2019
Reviewed
Jun 16, 2020
Last updated
Sep 4, 2024
The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking.
References