oss-sec mailing list archives
CVE-2022-46421: Apache Airflow Hive Provider: Hive Provider RCE vulnerability with hive_cli_params
From: Jarek Potiuk <potiuk () apache org>
Date: Tue, 20 Dec 2022 10:08:46 +0000
Severity: moderate
Description:
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software
Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.
Credit:
id_No2015429 of 3H Security Team (finder)
References:
https://github.com/apache/airflow/pull/28101
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2022-46421
Current thread:
- CVE-2022-46421: Apache Airflow Hive Provider: Hive Provider RCE vulnerability with hive_cli_params Jarek Potiuk (Dec 20)
