CVE-2023-35797
Apache Airflow Hive Provider Beeline remote code execution with Principal
9.8
CRITICAL
CVSS 3.1
EPSS 2.8%
描述
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal parameter. For this to be exploited it requires access to modifying the connection details. It is recommended updating provider version to 6.1.1 in order to avoid this vulnerability.
如何修補 CVE-2023-35797
要修補 CVE-2023-35797,請將受影響套件升級到下列已修補版本。
- —升級至 6.1.1 或更新版本
CVE-2023-35797 正在被利用嗎?
低 — EPSS 為 2.8%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 6.1.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |