---
id: CVE-2023-37415
aliases:
  - GHSA-4q2q-q5pw-2342
  - PYSEC-2026-1139
title: Apache Airflow Apache Hive Provider Improper Input Validation vulnerability
summary: Apache Airflow Apache Hive Provider Improper Input Validation vulnerability
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: apache-airflow-providers-apache-hive
product: apache-airflow-providers-apache-hive
ecosystem: pip
affected:
  - apache-airflow-providers-apache-hive < 6.1.2
patched:
  - apache-airflow-providers-apache-hive 6.1.2
published: '2023-07-13'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-4q2q-q5pw-2342'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-37415'
  - url: 'https://github.com/apache/airflow'
  - url: 'https://lists.apache.org/thread/9wx0jlckbnycjh8nj5qfwxo423zvm41k'
  - url: 'http://www.openwall.com/lists/oss-security/2023/07/12/3'
tags:
  - osv
  - pip
epss: 0.01586
epssPercentile: 0.74521
ingestedAt: '2026-07-08T18:25:45.521Z'
---

## Overview

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.

Patching on top of CVE-2023-35797
Before 6.1.2 the proxy_user option can also inject semicolon.

This issue affects Apache Airflow Apache Hive Provider: before 6.1.2.

It is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.

## Affected packages

- `apache-airflow-providers-apache-hive < 6.1.2`

## Remediation

Upgrade to a patched release:

- `apache-airflow-providers-apache-hive 6.1.2`
