You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@airflow.apache.org by Jarek Potiuk <po...@apache.org> on 2022/12/20 10:08:46 UTC

CVE-2022-46421: Apache Airflow Hive Provider: Hive Provider RCE vulnerability with hive_cli_params

Severity: moderate

Description:

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.

Credit:

id_No2015429 of 3H Security Team (finder)

References:

https://github.com/apache/airflow/pull/28101
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2022-46421