apache-airflow-providers-git is vulnerable to Improper Certificate Validation
59
Medium Risk
The Git provider runs its git-over-SSH operations with StrictHostKeyChecking=no by default, disabling SSH host-key verification. A party able to intercept the network path between a worker and the Git server can impersonate the server, capturing the SSH deploy key or injecting repository content. Deployments cloning over SSH with a deploy key are exposed. The fix verifies host keys by default and expects a configured known_hosts file.
You are affected if you are using a version that falls within the vulnerable range and you use the Git DAG bundle or Git provider to clone over SSH with a deploy key.
apache-airflow-providers-git is vulnerable to Improper Certificate Validation in versions 0.0.1 - 0.4.0.
Upgrade the apache-airflow-providers-git library to the patch version and configure a known_hosts file for your Git server.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant