oss-sec mailing list archives
CVE-2022-46421: Apache Airflow Hive Provider: Hive Provider RCE vulnerability with hive_cli_params
From: Jarek Potiuk <potiuk () apache org>
Date: Tue, 20 Dec 2022 10:08:46 +0000
Severity: moderate Description: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0. Credit: id_No2015429 of 3H Security Team (finder) References: https://github.com/apache/airflow/pull/28101 https://airflow.apache.org/ https://www.cve.org/CVERecord?id=CVE-2022-46421
Current thread:
- CVE-2022-46421: Apache Airflow Hive Provider: Hive Provider RCE vulnerability with hive_cli_params Jarek Potiuk (Dec 20)