CVE-2023-48362
CVSS V2 None
CVSS V3 None
Description
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file.
Users are recommended to upgrade to version 1.21.2, which fixes this issue.
Overview
- CVE ID
- CVE-2023-48362
- Assigner
- apache
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-07-24T07:45:43.686Z
- Last Modified Date
- 2024-07-24T07:45:43.686Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://lists.apache.org/thread/9tt0q4bdjwgw0dz0l9knqxjnpb5y6zsl | vendor-advisory |
http://www.openwall.com/lists/oss-security/2024/07/24/3 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-48362 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48362 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-07-25 13:00:28 | Added to TrackCVE |