Skip to content
Snippets Groups Projects

Compare revisions

Changes are shown as if the source revision was being merged into the target revision. Learn more about comparing revisions.

Source

Select target project
No results found
Select Git revision

Target

Select target project
  • gitlab-org/security-products/gemnasium-db
  • chubbymaggie/gemnasium-db
  • fcatteau/gemnasium-db
  • KJLJon/gemnasium-db
  • caneldem/gemnasium-db
  • Chest1/gemnasium-db
  • kayger44/gemnasium-db
  • brondsem/gemnasium-db
  • ifrenkel/gemnasium-db
  • rusher1/gemnasium-db
  • hristiyan.ivanov/gemnasium-db
  • gonzoyumo/gemnasium-db
  • robw-nom/gemnasium-db
  • westonsteimel/gemnasium-db
  • masahiro331/gemnasium-db
  • cmthomps/gemnasium-db
  • thomas.wesolowski/gemnasium-db
  • chamagwa/gemnasium-db
  • BanzaiMan/gemnasium-db
  • vishal.gupta6/gemnasium-db
  • candrews/gemnasium-db
  • attritionorg/gemnasium-db
  • dbolkensteyn/gemnasium-db
  • Snakefinder/gemnasium-db
  • masakura/gemnasium-db
  • ryan461/gemnasium-db
  • captncraig/gemnasium-db
  • rousey.thomas-heb/advisory-database-test
  • Ferada/gemnasium-db
  • elebow/gemnasium-db
  • Lapantera21/gemnasium-db
  • halfcrazy/gemnasium-db
  • neilcar/gemnasium-db
  • tywayne/gemnasium-db
  • vanschelven/gemnasium-db
  • mjkalasky2/gemnasium-db
  • bm402/gemnasium-db
  • reiner.gerecke/gemnasium-db
  • SunBK201/gemnasium-db
  • niklas.volcz/gemnasium-db
  • whostolebenfrog/gemnasium-db
  • PawelBarbarski/gemnasium-db
  • sify21/gemnasium-db
  • flagosatfluid/gemnasium-db
  • cflucasraab/gemnasium-db
  • wjrarneson78/gemnasium-db
  • Kamoot/gemnasium-db
  • fedemengo/gemnasium-db
  • mrtux/gemnasium-db
  • hkojha601/gemnasium-db
  • jason447/gemnasium-db
  • mschoettle/gemnasium-db
  • greengeko/gemnasium-db
  • aaronsmith1/gemnasium-db
  • dbonino/gemnasium-db
  • davidsalame/gemnasium-db
  • philipcunningham/gemnasium-db
  • BCsabaEngine/gemnasium-db
  • christian.dupuis/gemnasium-db
  • guidobonomi/gemnasium-db
  • bertuxdeveloper/gemnasium-db
  • matthewberrysys/gemnasium-db
  • aantonel-sysdig/gemnasium-db
  • irene221b/gemnasium-db
  • armbiant/gnome-go-advisory-database
  • awsactran/gemnasium-db
  • ayreon02/gemnasium-db
  • gitlab-community/gitlab-org/security-products/gemnasium-db
  • armbian33/go-advisory-database
69 results
Select Git revision
Show changes
Commits on Source (2)
---
identifier: "CVE-2024-29733"
identifiers:
- "CVE-2024-29733"
- "GHSA-3gg8-mc87-cq3h"
package_slug: "pypi/apache-airflow-providers-ftp"
title: "Improper Certificate Validation vulnerability in Apache Airflow FTP Provider"
description: "Improper Certificate Validation vulnerability in Apache Airflow FTP
Provider.\n\nThe FTP hook lacks complete certificate validation in FTP_TLS connections,
which can potentially be leveraged. Implementing proper certificate validation by
passing context=ssl.create_default_context() during FTP_TLS instantiation is used
as mitigation to validate the certificates properly.\n\nThis issue affects Apache
Airflow FTP Provider: before 3.7.0.\n\nUsers are recommended to upgrade to version
3.7.0, which fixes the issue."
date: "2024-04-24"
pubdate: "2024-04-21"
affected_range: "<3.7.0"
fixed_versions:
- "3.7.0"
affected_versions: "All versions before 3.7.0"
not_impacted: "All versions starting from 3.7.0"
solution: "Upgrade to version 3.7.0 or above."
urls:
- "https://nvd.nist.gov/vuln/detail/CVE-2024-29733"
- "https://github.com/advisories/GHSA-3gg8-mc87-cq3h"
- "https://github.com/apache/airflow/pull/38266"
- "https://docs.python.org/3/library/ssl.html#best-defaults"
- "https://github.com/apache/airflow"
- "https://github.com/apache/airflow/blob/95e26118b828c364755f3a8c96870f3591b01c31/airflow/providers/ftp/hooks/ftp.py#L280"
- "https://lists.apache.org/thread/265t5zbmtjs6h9fkw52wtp03nsbplky2"
uuid: "a2fdbff0-4461-48d5-bea4-649f4b6057fc"
cwe_ids:
- "CWE-295"
- "CWE-937"
- "CWE-1035"