Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-62728

Apache Hive: SQL injection in metastore delete column statistics requests

Technology

Apache Hive

CVSS Score

5.4 / 10.0

Affected Versions

Apache Hive 4.1.0 before 4.2.0

Upstream Fix

4.2.0

Published

November 26, 2025

OSSeva Coverage

Fixed upstream

Description

The Hive Metastore is open to SQL injection when it processes delete column statistics requests through its Thrift APIs. Only callers allowed to use the Thrift APIs directly can exploit it, and the vulnerable code cannot be reached when metastore.try.direct.sql is set to false, which the advisory recommends where the APIs are exposed and an upgrade is not possible.

Upstream record: NVD · CVE.org

Is your Apache Hive deployment affected?

If you're running Apache Hive 4.1.0 before 4.2.0, you need this patch. Book a discovery call to get covered.