9.0.4
4 years ago
2 days ago
Known vulnerabilities in the apache-airflow-providers-apache-hive package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Improper Input Validation via the How to fix Improper Input Validation? Upgrade | [,6.1.2) |
Affected versions of this package are vulnerable to Remote Code Execution (RCE) by bypassing the security check on the beeline How to fix Remote Code Execution (RCE)? Upgrade | [,6.1.1rc1) |
Affected versions of this package are vulnerable to Arbitrary Code Injection due to improper control of generation of code. How to fix Arbitrary Code Injection? Upgrade | [,6.0.0) |
Affected versions of this package are vulnerable to Improper Input Validation such that the parameters for Hive when beeline is used are not validated. How to fix Improper Input Validation? Upgrade | [,5.1.3) |
Affected versions of this package are vulnerable to Command Injection via How to fix Command Injection? Upgrade | [,5.0.0) |
Affected versions of this package are vulnerable to OS Command Injection which allows an attacker to execute arbitrary commands in the task execution context, without write access to DAG files. How to fix OS Command Injection? Upgrade | [,4.1.0) |