Loading HuntDB...

GHSA-rc58-qr9j-cpgw

GitHub Security Advisory

Apache Airflow Hive Provider vulnerable to Command Injection

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider before 5.0.0.

Affected Packages

PyPI apache-airflow-providers-apache-hive
Affected versions: 0 (fixed in 5.0.0)

Related CVEs

Key Information

GHSA ID
GHSA-rc58-qr9j-cpgw
Published
December 20, 2022 12:30 PM
Last Modified
January 4, 2023 1:54 PM
CVSS Score
9.0 /10
Primary Ecosystem
PyPI
Primary Package
apache-airflow-providers-apache-hive
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 12, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.