CVE Database
/

CVE-2023-48362

Back to search

CVE-2023-48362

Published: Jul 24, 2024

Modified: Feb 13, 2025

PUBLISHED

Description

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.

VendorProductVersions

Apache Software Foundation

Apache Drill

affected
1.19.0 - < 1.21.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now