Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2018-1282
Apache Hive: JDBC driver PreparedStatement escaping can be bypassed
Technology
Apache Hive
CVSS Score
9.1 / 10.0
Affected Versions
Apache Hive JDBC driver 0.7.1 to 2.3.2
Upstream Fix
2.3.3
Published
April 5, 2018
OSSeva Coverage
Fixed upstream
Description
Carefully crafted arguments bypass the escaping the Hive JDBC driver applies in its PreparedStatement implementation, so applications that pass user input to it are open to SQL injection. The advisory notes that the 2.3.3 driver does not talk to HiveServer2 2.1.1 or earlier, so older clusters may need a server upgrade too.
Is your Apache Hive deployment affected?
If you're running Apache Hive JDBC driver 0.7.1 to 2.3.2, you need this patch. Book a discovery call to get covered.