CVE-2023-48362: Apache Drill: XXE Vulnerability in XML Format Reader
Published Jul 24, 2024
·Updated
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.
Affected Software
2 affected componentsFixes available
Apache Drill>=1.9.0<1.21.2
maven/org.apache.drill.exec:drill-java-exec>=1.19.0<1.21.2
1.21.2
Event History
Jul 24, 2024
CVE Published
via MITRE·07:45 AM
Data Sourced
via MITRE·07:45 AM
DescriptionWeakness
Advisory Published
via GitHub·09:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-48362?
CVE-2023-48362 has been classified as a critical vulnerability due to its potential for unauthorized file access and remote command execution.
2
How do I fix CVE-2023-48362?
To fix CVE-2023-48362, upgrade Apache Drill to version 1.21.2 or greater.
3
What versions of Apache Drill are affected by CVE-2023-48362?
CVE-2023-48362 affects Apache Drill versions 1.19.0 through 1.21.1.
4
What type of vulnerability is CVE-2023-48362?
CVE-2023-48362 is an XML External Entity (XXE) vulnerability in Apache Drill's XML Format Plugin.
5
Can CVE-2023-48362 lead to data breaches?
Yes, CVE-2023-48362 can lead to data breaches by allowing attackers to read sensitive files on remote systems.