High severity8.8NVD Advisory· Published Jul 13, 2023· Updated Jun 17, 2026
CVE-2023-37415
CVE-2023-37415
Description
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.
Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon.
This issue affects Apache Airflow Apache Hive Provider: before 6.1.2.
It is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflow-providers-apache-hivePyPI | < 6.1.2 | 6.1.2 |
Affected products
3- cpe:2.3:a:apache:apache-airflow-providers-apache-hive:*:*:*:*:*:*:*:*Range: <6.1.2
- Range: 0
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2023/07/12/3nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-4q2q-q5pw-2342ghsaADVISORY
- lists.apache.org/thread/9wx0jlckbnycjh8nj5qfwxo423zvm41knvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-37415ghsaADVISORY
News mentions
0No linked articles in our index yet.