GHSA-v62g-jwj9-rfvx
HIGHCVE-2023-48362XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.
- Affected
- >= 1.19.0, < 1.21.2
- Fixed in
- 1.21.2
- Weakness
- CWE-611
- Published
- 2024-07-24
- Source
- github