CVE-2023-48362

CVE-2023-48362: Apache Drill: XXE Vulnerability in XML Format Reader

Vendor Apache Software Foundation
Product Apache Drill
Weakness CWE-611 · XXE
Published July 24, 2024
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.

Key dates

Disclosure timeline

July 24, 2024 CVE published
February 13, 2025 Record updated