apache-airflow-providers-apache-hive
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting apache-airflow-providers-apache-hivepage 1 of 1
- CVE-2022-41131HIGHCVSS 7.8EG 7.8✓ Fixed in 4.1.02022-11-22
vulnerable: 1.0.0 ... 4.1.0rc1 (45 versions)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without…
- CVE-2022-46421CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.0.02022-12-20
vulnerable: 1.0.0 ... 5.0.0rc1 (50 versions)
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.
- CVE-2023-25696CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.1.32023-02-24
vulnerable: 1.0.0 ... 5.1.3rc1 (59 versions)
Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.
- CVE-2023-28706CRITICALCVSS 9.8EG 9.8✓ Fixed in 6.0.02023-04-07
vulnerable: 1.0.0 ... 6.0.0rc1 (61 versions)
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.
- CVE-2023-35797CRITICALCVSS 9.8EG 9.8✓ Fixed in 6.1.12023-07-03
vulnerable: 1.0.0 ... 6.1.1rc1 (66 versions)
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check t…
- CVE-2023-37415HIGHCVSS 8.8EG 8.8✓ Fixed in 6.1.22023-07-13
vulnerable: 1.0.0 ... 6.1.2rc2 (68 versions)
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflo…
Check whether apache-airflow-providers-apache-hive is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for apache-airflow-providers-apache-hive CVEs against the assets you own.
Start Free Scan →