Apache / Hive
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-49845 | Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths | CRITICAL | 9.8 | Aug 25, 2026 |
| CVE-2026-55976 | Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url | CRITICAL | 9.1 | Aug 25, 2026 |
| CVE-2026-53561 | Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive user | HIGH | 7.4 | Aug 25, 2026 |
| CVE-2025-62728 | Apache Hive: SQL injection vulnerability when processing delete column statistics requests via the HMS Thrift APIs | HIGH | 8.6 | Nov 26, 2025 |
| CVE-2024-29869 | Apache Hive: Credentials file created with non restrictive permissions | MEDIUM | 5.5 | Jan 28, 2025 |
| CVE-2024-23953 | Apache Hive: Timing Attack Against Signature in LLAP util | MEDIUM | 6.5 | Jan 28, 2025 |
| CVE-2024-23945 | Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails | HIGH | 8.7 | Dec 23, 2024 |
| CVE-2022-41137 | Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore | HIGH | 7.2 | Dec 5, 2024 |
| CVE-2023-35701 | Apache Hive: Arbitrary command execution via JDBC driver | MEDIUM | 6.6 | May 3, 2024 |
| CVE-2021-34538 | Apache Hive Security vulnerability in Hive with UDFs | HIGH | 7.5 | Jul 16, 2022 |
| CVE-2020-1926 | Timing attack in Cookie signature verification | MEDIUM | 5.9 | Mar 16, 2021 |
| CVE-2020-13949 | libthrift: potential DoS when processing untrusted payloads | HIGH | 7.5 | Feb 12, 2021 |
| CVE-2018-21234 | Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set. | CRITICAL | 9.8 | May 21, 2020 |
| CVE-2018-1314 | In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized u… | MEDIUM | 4.3 | Nov 8, 2018 |
| CVE-2018-11777 | In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql sta… | HIGH | 8.1 | Nov 8, 2018 |
| CVE-2018-1315 | hive: 'COPY FROM FTP' feature allows malicious FTP server to write arbitrary files to the cluster | MEDIUM | 6.3 | Apr 5, 2018 |
| CVE-2018-1284 | hive: Mishandled input in UDFXPathUtil.java allows users to access arbitrary files via crafted XML | MEDIUM | 6.5 | Apr 5, 2018 |
| CVE-2018-1282 | hive: Improper input validation in jdbc/HivePreparedStatement.java allows for SQL injection | CRITICAL | 9.1 | Apr 5, 2018 |
| CVE-2017-12625 | Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views… | MEDIUM | 4.3 | Nov 1, 2017 |
| CVE-2016-3083 | Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificat… | HIGH | 7.5 | May 30, 2017 |
| CVE-2015-7521 | The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows att… | HIGH | 8.3 | Jan 29, 2016 |
| CVE-2015-1772 | Hive: authentication vulnerability in HiveServer2 | HIGH | 7.3 | Dec 21, 2015 |
| CVE-2014-0228 | Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statement… | LOW | 3.5 | Nov 16, 2014 |
Showing 1 to 23 of 23 CVEs