CVE-2024-25141: Apache Apache-Airflow-Providers-Mongo
Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.
Affected products
- Apache Apache-Airflow-Providers-Mongo: from 1.0.0, before 4.0.0 (fixed in 4.0.0)
Published 2024-02-20. Last modified 2026-06-17.