XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file.
Users are recommended to upgrade to version 1.21.2, which fixes this issue.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2024/07/24/3 | Mailing List |
https://lists.apache.org/thread/9tt0q4bdjwgw0dz0l9knqxjnpb5y6zsl | Mailing List Vendor Advisory |
Configurations
History
10 Sep 2024, 16:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2024/07/24/3 - Mailing List | |
References | () https://lists.apache.org/thread/9tt0q4bdjwgw0dz0l9knqxjnpb5y6zsl - Mailing List, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Apache
Apache drill |
|
CPE | cpe:2.3:a:apache:drill:*:*:*:*:*:*:*:* |
01 Aug 2024, 13:45
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
24 Jul 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
24 Jul 2024, 12:55
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
24 Jul 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-24 08:15
Updated : 2024-09-10 16:31
NVD link : CVE-2023-48362
Mitre link : CVE-2023-48362
CVE.ORG link : CVE-2023-48362
JSON object : View
Products Affected
apache
- drill
CWE
CWE-611
Improper Restriction of XML External Entity Reference