High
CVE-2022-46421
Apache Airflow Hive Provider could allow a remote attacker to execute arbitrary commands on the system, caused by improper input validation. By sending a specially-crafted request using the hive_cli_params parameter, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
Apache
Upgrade to the latest version of Apache Airflow Hive Provider, available from the Apache Airflow GIT Repository.