CVE-2023-37415

CVE-2023-37415: Apache Airflow Apache Hive Provider: Improper Input Validation in Hive Provider with proxy_user

Vendor Apache Software Foundation
Product Apache Airflow Apache Hive Provider
Weakness CWE-20 · Input validation
Published July 13, 2023
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflow Apache Hive Provider: before 6.1.2. It is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.

Key dates

Disclosure timeline

July 13, 2023 CVE published
February 13, 2025 Record updated