hive: 'COPY FROM FTP' feature allows malicious FTP server to write arbitrary files to the cluster
Published Apr 5, 2018
6.3
MEDIUMCVSS 3.0
EPSS 1.75%
Description
In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statement is run using HPL/SQL extension to Hive, a compromised/malicious FTP server can cause the file to be written to an arbitrary location on the cluster where the command is run from. This is because FTP client code in HPL/SQL does not verify the destination location of the downloaded file. This does not affect hive cli user and hiveserver2 user as hplsql is a separate command line script and needs to be invoked differently.
Affected products
-
- Version 2.1.0 to 2.3.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Hive | n/a |
|
No data.
Red Hat JBoss Fuse Integration Service 2
hive
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Fuse Integration Service 2 | hive | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.75% (0.01746) | 76.97th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.78% (0.01780) | 75.29th | v5 (v2026.06.15) |
| Mar 17, 2025 | 1.04% (0.01038) | 75.87th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.15% (0.00155) | 53.19th | v3 (v2023.03.01) |
| Feb 12, 2024 | 0.15% (0.00155) | 50.57th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.14% (0.00143) | 50.03th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00071) | 28.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.24% (0.01241) | 30.13th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.24% (0.01241) | 0.00th | v1 |
References (7)
- https://access.redhat.com/security/cve/CVE-2018-1315 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1564364 Issue Tracking
- https://github.com/advisories/GHSA-p639-xxv5-j383 Advisory
- https://lists.apache.org/thread.html/d5da94ef60312c01a8d2348466680d1b5fb70702c71a3e84e94f7933%40%3Cdev.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/d5da94ef60312c01a8d2348466680d1b5fb70702c71a3e84e94f7933@%3Cdev.hive.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2018-1315
- https://www.cve.org/CVERecord?id=CVE-2018-1315
Change history (0)
No recorded changes yet.