CVE-2018-20245

HIGH

Apache Airflow <1.10.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking.

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 58.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-295
Status published
Products (2)
apache/airflow < 1.10.1
pypi/apache-airflow 0 - 1.10.1PyPI
Published Jan 23, 2019
Tracked Since Feb 18, 2026