oss-sec mailing list archives
CVE-2023-25696: Apache Airflow Hive Provider Beeline RCE
From: Jarek Potiuk <potiuk () apache org>
Date: Thu, 23 Feb 2023 17:45:35 +0000
Severity: moderate Description: Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. Credit: id_No2015429 of 3H Secruity Team (finder) References: https://github.com/apache/airflow/pull/29502 https://airflow.apache.org/ https://www.cve.org/CVERecord?id=CVE-2023-25696
Current thread:
- CVE-2023-25696: Apache Airflow Hive Provider Beeline RCE Jarek Potiuk (Feb 23)