cve/2023/CVE-2023-48362.md

18 lines
799 B
Markdown
Raw Normal View History

2024-07-25 21:25:12 +00:00
### [CVE-2023-48362](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48362)
![](https://img.shields.io/static/v1?label=Product&message=Apache%20Drill&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=1.19.0%3C%201.21.2%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-611%20Improper%20Restriction%20of%20XML%20External%20Entity%20Reference&color=brighgreen)
### Description
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file.Users are recommended to upgrade to version 1.21.2, which fixes this issue.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/tanjiti/sec_profile