Skip to main content

Vendor/product archive

apache / drill CVEs

Beta · best-effort

6 CVEs tagged to apache / drill0 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-48362

Published Jul 24, 2024

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0201

Published May 23, 2019

An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the req…

CVSS 5.9 · Medium

CVE-2017-12630

Published Dec 18, 2017

In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example:…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1