Apache Airflow Hive Provider Beeline RCE with Principal
CVE-2023-35797
9.8CRITICAL
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 3 July 2023
What is CVE-2023-35797?
The Apache Airflow Hive Provider prior to version 6.1.1 contains an improper input validation vulnerability that allows an attacker to bypass security checks and potentially execute remote code through the manipulation of the principal parameter. This exploit requires access to modify connection details, highlighting the importance of securing these configurations. To mitigate this risk, it is crucial to update to version 6.1.1 or later.
Affected Version(s)
Apache Airflow Apache Hive Provider 0 < 6.1.1