Back to search
CVE-2023-48362
Published: Jul 24, 2024
Modified: Feb 13, 2025
PUBLISHED
Description
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Drill | affected 1.19.0 - < 1.21.2 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now