Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2025-62728
Apache Hive: SQL injection in metastore delete column statistics requests
Technology
Apache Hive
CVSS Score
5.4 / 10.0
Affected Versions
Apache Hive 4.1.0 before 4.2.0
Upstream Fix
4.2.0
Published
November 26, 2025
OSSeva Coverage
Fixed upstream
Description
The Hive Metastore is open to SQL injection when it processes delete column statistics requests through its Thrift APIs. Only callers allowed to use the Thrift APIs directly can exploit it, and the vulnerable code cannot be reached when metastore.try.direct.sql is set to false, which the advisory recommends where the APIs are exposed and an upgrade is not possible.
Is your Apache Hive deployment affected?
If you're running Apache Hive 4.1.0 before 4.2.0, you need this patch. Book a discovery call to get covered.