Loading HuntDB...

GHSA-5cvg-9pp5-mxcj

GitHub Security Advisory

Apache Airflow Hive Provider vulnerable to code injection

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

Apache Software Foundation's Apache Airflow Hive Provider before 6.0.0 is vulnerable to improper control of generation of code.

Affected Packages

PyPI apache-airflow-providers-apache-hive
Affected versions: 0 (fixed in 6.0.0)

Related CVEs

Key Information

GHSA ID
GHSA-5cvg-9pp5-mxcj
Published
April 7, 2023 3:30 PM
Last Modified
April 14, 2023 8:31 PM
CVSS Score
9.0 /10
Primary Ecosystem
PyPI
Primary Package
apache-airflow-providers-apache-hive
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 12, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.