Apache Airflow FTP是美国Apache基金会的一个FTP服务器软件。 Apache Airflow FTP 3.15.1之前版本存在加密问题漏洞,该漏洞源于FTPSHook.get_conn()创建了ftplib.FTP_TLS连接但未调用prot_p(),导致数据通道以明文传输,可能被网络攻击者观察数据连接,从而暴露传输中的文件内容和凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Airflow FTP provider | < 3.15.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow FTP provider | 0 ~ 3.15.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57914 | Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures | |
| CVE-2026-57915 | Apache Kerby: Kerberos Pre-Authentication Bypass | |
| CVE-2025-55017 | Apache IoTDB: Path Traversal Vulnerability | |
| CVE-2025-64152 | Apache IoTDB: Path Traversal Vulnerability |
No comments yet