cve/2023/CVE-2023-48362.md
2024-07-25 21:25:12 +00:00

799 B

CVE-2023-48362

Description

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file.Users are recommended to upgrade to version 1.21.2, which fixes this issue.

POC

Reference

No PoCs from references.

Github