CVE-2023-39441
23.08.2023, 16:15
Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, andApache Airflow before 2.7.0 are affected by theValidation of OpenSSL Certificate vulnerability. The default SSL context with SSL library did not check a server's X.509certificate. Instead, the code accepted any certificate, which couldresult in the disclosure of mail server credentials or mail contentswhen the client connects to an attacker in a MITM position. Users are strongly advised to upgrade to Apache Airflow version 2.7.0 or newer, Apache Airflow IMAP Provider version 3.3.0 or newer, and Apache Airflow SMTP Provider version 1.3.0 or newer to mitigate the risk associated with this vulnerabilityEnginsight
Vendor | Product | Version |
---|---|---|
apache | airflow | 𝑥 < 2.7.0 |
apache | apache-airflow-providers-imap | 𝑥 < 3.3.0 |
apache | apache-airflow-providers-smtp | 𝑥 < 1.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References