Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2018-1282

Apache Hive: JDBC driver PreparedStatement escaping can be bypassed

Technology

Apache Hive

CVSS Score

9.1 / 10.0

Affected Versions

Apache Hive JDBC driver 0.7.1 to 2.3.2

Upstream Fix

2.3.3

Published

April 5, 2018

OSSeva Coverage

Fixed upstream

Description

Carefully crafted arguments bypass the escaping the Hive JDBC driver applies in its PreparedStatement implementation, so applications that pass user input to it are open to SQL injection. The advisory notes that the 2.3.3 driver does not talk to HiveServer2 2.1.1 or earlier, so older clusters may need a server upgrade too.

Upstream record: NVD · CVE.org

Is your Apache Hive deployment affected?

If you're running Apache Hive JDBC driver 0.7.1 to 2.3.2, you need this patch. Book a discovery call to get covered.