GHSA-4q2q-q5pw-2342
GitHub Security Advisory
Apache Airflow Apache Hive Provider Improper Input Validation vulnerability
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.
Patching on top of CVE-2023-35797
Before 6.1.2 the proxy_user option can also inject semicolon.
This issue affects Apache Airflow Apache Hive Provider: before 6.1.2.
It is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.
Affected Packages
PyPI
apache-airflow-providers-apache-hive
Affected versions:
0
(fixed in 6.1.2)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.