CVE-2023-28706: Apache Airflow Hive Provider
Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.
Affected products
- Apache Airflow Hive Provider: before 6.0.0 (fixed in 6.0.0)
Published 2023-04-07. Last modified 2026-06-17.