CVE-2023-25696
published 2023-02-24CVE-2023-25696: Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.98%
78.2th percentile
Improper Input Validation vulnerability in the Apache Airflow Hive Provider.
This issue affects Apache Airflow Hive Provider versions before 5.1.3.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache-airflow-providers-apache-hive | < 5.1.3 | 5.1.3 |
| apache | apache-airflow-providers-apache-hive | >= 0 < 5.1.3 | 5.1.3 |
| apache_software_foundation | apache_airflow_hive_provider | < 5.1.3 | 5.1.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Airflow Hive Provider Improper Input Validation vulnerability
ghsa·2023-02-24
CVE-2023-25696 [CRITICAL] CWE-20 Apache Airflow Hive Provider Improper Input Validation vulnerability
Apache Airflow Hive Provider Improper Input Validation vulnerability
Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.
OSV
Apache Airflow Hive Provider Improper Input Validation vulnerability
osv·2023-02-24
CVE-2023-25696 [CRITICAL] Apache Airflow Hive Provider Improper Input Validation vulnerability
Apache Airflow Hive Provider Improper Input Validation vulnerability
Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-24
Published