CVE-2022-46421

CWE-77Command Injection4 documents4 sources
Severity
9.8CRITICAL
EPSS
31.2%
top 3.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Patches

🔴Vulnerability Details

3
OSV
Apache Airflow Hive Provider vulnerable to Command Injection2022-12-20
GHSA
Apache Airflow Hive Provider vulnerable to Command Injection2022-12-20
CVEList
Apache Airflow Hive Provider: Hive Provider RCE vulnerability with hive_cli_params2022-12-20
CVE-2022-46421 (CRITICAL CVSS 9.8) | Improper Neutralization of Special | cvebase.io