https://seclists.org/oss-sec/2024/q3/109: CVE-2023-48362: Apache Drill: XXE Vulnerability in XML Format ader
Published Jul 24, 2024
·Updated
Affected Software
1 affected component
Apache Drill<1.21.2
Frequently Asked Questions
1
What is the severity of CVE-2023-48362?
The severity of CVE-2023-48362 is classified as moderate.
2
Which versions of Apache Drill are affected by CVE-2023-48362?
Apache Drill versions 1.19.0 before 1.21.2 are affected by CVE-2023-48362.
3
How do I fix CVE-2023-48362?
To fix CVE-2023-48362, upgrade Apache Drill to version 1.21.2 or later.
4
What type of vulnerability is CVE-2023-48362?
CVE-2023-48362 is an XML External Entity (XXE) vulnerability in the XML Format Plugin of Apache Drill.
5
What risks does CVE-2023-48362 pose to users?
CVE-2023-48362 allows an attacker to read any file on a remote file system or execute commands via a malicious XML file.