Apache Drill is vulnerable to cross-site scripting (XSS) attacks. The library does not properly sanitize the user input string in the query page or in the profile page, allowing a malicious user to inject and execute arbitrary Javascript.
CPE | Name | Operator | Version |
---|---|---|---|
drill : exec : java execution engine | le | 1.11.0 |