High severityNVD Advisory· Published Jul 24, 2024· Updated Feb 13, 2025
Apache Drill: XXE Vulnerability in XML Format Reader
CVE-2023-48362
Description
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.drill.exec:drill-java-execMaven | >= 1.19.0, < 1.21.2 | 1.21.2 |
Affected products
2- Apache Software Foundation/Apache Drillv5Range: 1.19.0
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-v62g-jwj9-rfvxghsaADVISORY
- lists.apache.org/thread/9tt0q4bdjwgw0dz0l9knqxjnpb5y6zslghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-48362ghsaADVISORY
- www.openwall.com/lists/oss-security/2024/07/24/3ghsaWEB
- github.com/apache/drill/commit/0e88b7a5101d24c561a2a3efb12d7a3b3f7933f3ghsaWEB
- issues.apache.org/jira/browse/DRILL-8461ghsaWEB
News mentions
0No linked articles in our index yet.