CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. It affects Apache. It may be remotely exploitable.
CVE
CVE-2023-48362
Severity
HIGH
CVSS
8.8
EPSS
0.75%
Apache
Original NVD Description
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)