Apache Hive 4.2.1 之前版本(所有平台)的 Hive Metastore 中,当启用直接 SQL(默认启用)时,存在 SQL 注入漏洞,位于通过直接 SQL 解析分区名称(partition-name resolution)的过程中。经过身份认证并有权访问 Hive Metastore API 的攻击者,可以通过在 Metastore RPC 请求中构造恶意分区名称,读取、修改或影响非预期的分区元数据(包括统计信息更新、截断目标以及文件元数据缓存操作)。建议用户升级至 4.2.1 版本以修复此问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Hive | 4.0.0≤ 4.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Hive | 4.0.0 ~ 4.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55976 | Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on | |
| CVE-2026-53561 | Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token v | |
| CVE-2026-49050 | Apache DolphinScheduler: General user can mint admin access tokens via /access-tokens |
No comments yet