-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| apache-airflow-providers-mongo | pip | < 4.0.0 | 4.0.0 |
The vulnerability stems from how SSL configuration was handled in the MongoDB connection setup. The patch in apache/airflow#37214 shows the get_conn method was modified to remove insecure defaults. Previously, when SSL was enabled, certificate validation was disabled by default through implicit 'allow_insecure' behavior (via CERT_NONE/True values). This matches the CWE-295 description of improper certificate validation and aligns with the CVE description about unexpected insecure defaults.
Ongoing coverage of React2Shell