oss-sec mailing list archives

CVE-2022-46421: Apache Airflow Hive Provider: Hive Provider RCE vulnerability with hive_cli_params


From: Jarek Potiuk <potiuk () apache org>
Date: Tue, 20 Dec 2022 10:08:46 +0000

Severity: moderate

Description:

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software 
Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.

Credit:

id_No2015429 of 3H Security Team (finder)

References:

https://github.com/apache/airflow/pull/28101
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2022-46421


Current thread: