Description
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-providers-google` 22.0.0 or later.
Problem types
CWE-322: (Key Exchange without Entity Authentication)
Product status
Any version before 22.0.0
Credits
Jarek Potiuk
References
github.com/apache/airflow/pull/66746
lists.apache.org/thread/3lpj7ppwxp7jtp81rnxk75xvln7qd7h2