Apache Airflow Hive Provider: Hive Provider RCE vulnerability with hive_cli_params
CVE-2022-46421
9.8CRITICAL
What is CVE-2022-46421?
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.
Affected Version(s)
Apache Airflow Hive Provider 0 < 5.0.0