SCA: security update for apache-airflow, apache-airflow-providers-imap, apache-airflow-providers-smtp (GHSA-5f35-pq34-c87q)

medium Tenable Self-Hosted Container Security Plugin ID 410783

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow
before 2.7.0 are affected by the Validation of OpenSSL Certificate vulnerability. The default SSL context
with SSL library did not check a server's X.509 certificate. Instead, the code accepted any certificate,
which could result in the disclosure of mail server credentials or mail contents when the client connects
to an attacker in a MITM position. Users are strongly advised to upgrade to Apache Airflow version 2.7.0
or newer, Apache Airflow IMAP Provider version 3.3.0 or newer, and Apache Airflow SMTP Provider version
1.3.0 or newer to mitigate the risk associated with this vulnerability (CVE-2023-39441)

See Also

https://github.com/advisories/GHSA-5f35-pq34-c87q

Plugin Details

Severity: Medium

ID: 410783

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2023-39441

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/23/2023

Vulnerability Publication Date: 8/23/2023

Reference Information

CVE: CVE-2023-39441

cwe: CWE-295