PYSEC-2026-1139
Dashboard / Vulnerabilities / PYSEC-2026-1139
PYSEC-2026-1139
Summary: Apache Airflow Apache Hive Provider Improper Input Validation vulnerability
Details: Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider. Patching on top of CVE-2023-35797 Before 6.1.2 the proxy_user option can also inject semicolon. This issue affects Apache Airflow Apache Hive Provider: before 6.1.2. It is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-37415, https://github.com/apache/airflow, https://lists.apache.org/thread/9wx0jlckbnycjh8nj5qfwxo423zvm41k, http://www.openwall.com/lists/oss-security/2023/07/12/3, https://pypi.org/project/apache-airflow-providers-apache-hive, https://github.com/advisories/GHSA-4q2q-q5pw-2342
Affected packages
Package
Name: apache-airflow-providers-apache-hive
Purl: pkg:pypi/apache-airflow-providers-apache-hive
Affected ranges
Type: ECOSYSTEM
Events:
