Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-v62g-jwj9-rfvx: XML External Entity Reference (XXE) in the XML Format Plugin in Apache Drill

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.

ghsa
#apache#git

XML External Entity Reference (XXE) in the XML Format Plugin in Apache Drill

Moderate severity GitHub Reviewed Published Jul 24, 2024 to the GitHub Advisory Database • Updated Jul 24, 2024

ghsa: Latest News

GHSA-27wf-5967-98gx: Kubernetes kubelet arbitrary command execution