First published: Fri Apr 07 2023(Updated: )
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Airflow Hive Provider | <6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28706 has not been assigned a CVSS score, but it poses a potential risk due to improper control of code generation.
To mitigate CVE-2023-28706, upgrade to Apache Airflow Hive Provider version 6.0.0 or later.
CVE-2023-28706 is caused by improper control of code generation in versions before 6.0.0 of Apache Airflow Hive Provider.
Any user of Apache Airflow Hive Provider versions prior to 6.0.0 is affected by CVE-2023-28706.
CVE-2023-28706 impacts the Apache Airflow Hive Provider specifically in versions before 6.0.0.