XML External Entity Reference (XXE) in the XML Format Plugin in Apache Drill
High severity
GitHub Reviewed
Published
Jul 24, 2024
to the GitHub Advisory Database
•
Updated Sep 10, 2024
Package
Affected versions
>= 1.19.0, < 1.21.2
Patched versions
1.21.2
Description
Published by the National Vulnerability Database
Jul 24, 2024
Published to the GitHub Advisory Database
Jul 24, 2024
Reviewed
Jul 24, 2024
Last updated
Sep 10, 2024
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.
References