CVE-2023-28706: Apache Airflow Hive Provider Beeline Remote Command Execution
Published Apr 7, 2023
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.
Affected Software
1 affected component
Apache Airflow Hive Provider<6.0.0
Event History
Apr 7, 2023
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28706?
CVE-2023-28706 has not been assigned a CVSS score, but it poses a potential risk due to improper control of code generation.
2
How do I fix CVE-2023-28706?
To mitigate CVE-2023-28706, upgrade to Apache Airflow Hive Provider version 6.0.0 or later.
3
What causes CVE-2023-28706?
CVE-2023-28706 is caused by improper control of code generation in versions before 6.0.0 of Apache Airflow Hive Provider.
4
Who is affected by CVE-2023-28706?
Any user of Apache Airflow Hive Provider versions prior to 6.0.0 is affected by CVE-2023-28706.
5
What products are impacted by CVE-2023-28706?
CVE-2023-28706 impacts the Apache Airflow Hive Provider specifically in versions before 6.0.0.