CVE-2023-25696: Apache Airflow Hive Provider Beeline RCE
Published Feb 24, 2023
·Updated
Improper Input Validation vulnerability in the Apache Airflow Hive Provider.
This issue affects Apache Airflow Hive Provider versions before 5.1.3.
Affected Software
1 affected component
Apache Apache-airflow-providers-apache-hive<5.1.3
Remediation
Patch Available
Event History
Feb 24, 2023
CVE Published
via MITRE·11:48 AM
Data Sourced
via MITRE·11:48 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-25696?
CVE-2023-25696 is an Improper Input Validation vulnerability in the Apache Airflow Hive Provider.
2
Which versions of Apache Airflow Hive Provider are affected by CVE-2023-25696?
CVE-2023-25696 affects Apache Airflow Hive Provider versions before 5.1.3.
3
What is the severity of CVE-2023-25696?
CVE-2023-25696 has a severity rating of 9.8 (critical).
4
How can I fix CVE-2023-25696?
To fix CVE-2023-25696, upgrade Apache Airflow Hive Provider to version 5.1.3 or later.
5
Where can I find more information about CVE-2023-25696?
You can find more information about CVE-2023-25696 on the Apache Airflow GitHub repository and Apache mailing list.