CVE-2018-20245
published 2019-01-23CVE-2018-20245: The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
1.02%
59.2th percentile
The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 1.10.1 | 1.10.1 |
| apache_software_foundation | apache_airflow | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Certificate Validation in Apache Airflow
osv·2019-01-25
CVE-2018-20245 [HIGH] Improper Certificate Validation in Apache Airflow
Improper Certificate Validation in Apache Airflow
The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking.
GHSA
Improper Certificate Validation in Apache Airflow
ghsa·2019-01-25
CVE-2018-20245 [HIGH] CWE-295 Improper Certificate Validation in Apache Airflow
Improper Certificate Validation in Apache Airflow
The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking.
OSV
CVE-2018-20245: The LDAP auth backend (airflow
osv·2019-01-23
CVE-2018-20245 CVE-2018-20245: The LDAP auth backend (airflow
The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-01-23
Published