Loading HuntDB...

GHSA-4q2q-q5pw-2342

GitHub Security Advisory

Apache Airflow Apache Hive Provider Improper Input Validation vulnerability

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.

Patching on top of CVE-2023-35797
Before 6.1.2 the proxy_user option can also inject semicolon.

This issue affects Apache Airflow Apache Hive Provider: before 6.1.2.

It is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.

Affected Packages

PyPI apache-airflow-providers-apache-hive
Affected versions: 0 (fixed in 6.1.2)

Related CVEs

Key Information

GHSA ID
GHSA-4q2q-q5pw-2342
Published
July 13, 2023 9:30 AM
Last Modified
February 13, 2025 7:00 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
apache-airflow-providers-apache-hive
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.