CVE-2023-48362
published 2024-07-24CVE-2023-48362: XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.75%
50.7th percentile
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file.
Users are recommended to upgrade to version 1.21.2, which fixes this issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | drill | >= 1.9.0 < 1.21.2 | 1.21.2 |
| apache_software_foundation | apache_drill | >= 1.19.0 < 1.21.2 | 1.21.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
XML External Entity Reference (XXE) in the XML Format Plugin in Apache Drill
ghsa·2024-07-24
CVE-2023-48362 [HIGH] CWE-611 XML External Entity Reference (XXE) in the XML Format Plugin in Apache Drill
XML External Entity Reference (XXE) in the XML Format Plugin in Apache Drill
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.
OSV
XML External Entity Reference (XXE) in the XML Format Plugin in Apache Drill
osv·2024-07-24
CVE-2023-48362 [HIGH] XML External Entity Reference (XXE) in the XML Format Plugin in Apache Drill
XML External Entity Reference (XXE) in the XML Format Plugin in Apache Drill
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-24
Published