Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Hive — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Apache Hive, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with Apache Hive, focusing specifically on known software weaknesses and their impact on the product. It collects records of security defects, such as injection flaws or access control issues, covering advisories published across recent years. Visitors can use this resource to track the vendor’s security releases, understand the prevalence of specific weakness classes, and review the vulnerability history for this particular product. The entries are structured to facilitate analysis of trends in security patches and to support risk assessment for environments running Apache Hive.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-49845 Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths CWE-94 - - 2026-08-25
CVE-2026-55976 Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url CWE-918 - - 2026-08-25
CVE-2026-53561 Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive user CWE-287 - - 2026-08-25
CVE-2025-62728 Apache Hive: SQL injection vulnerability when processing delete column statistics requests via the HMS Thrift APIs CWE-89 8.8AI High AI 2025-11-26
CVE-2024-29869 Apache Hive: Credentials file created with non restrictive permissions CWE-732 6.5 - 2025-01-28
CVE-2024-23953 Apache Hive: Timing Attack Against Signature in LLAP util CWE-208 6.5 - 2025-01-28
CVE-2024-23945 Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails CWE-209 8.2 - 2024-12-23
CVE-2022-41137 Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore CWE-502 8.8 - 2024-12-05
CVE-2023-35701 Apache Hive: Arbitrary command execution via JDBC driver CWE-94 8.8AI High AI 2024-05-03
CVE-2021-34538 Apache Hive Security vulnerability in Hive with UDFs CWE-306 7.5 - 2022-07-16
CVE-2020-1926 Timing attack in Cookie signature verification CWE-208 5.9 - 2021-03-16
CVE-2018-1314 Apache Hive 安全漏洞 4.3 - 2018-11-08
CVE-2018-11777 Apache Hive HiveServer2 安全漏洞 8.3 - 2018-11-08
CVE-2018-1315 Apache Hive 安全特征问题漏洞 5.3 - 2018-04-05
CVE-2018-1284 Apache Hive 信息泄露漏洞 5.3 - 2018-04-05
CVE-2018-1282 Apache Hive JDBC驱动程序SQL注入漏洞 9.8 - 2018-04-05
CVE-2017-12625 Apache Hive 信息泄露漏洞 5.3 - 2017-11-01
CVE-2016-3083 Apache Hive 安全漏洞 - - 2017-05-30

All 18 known CVE vulnerabilities affecting Apache Hive with full Chinese analysis, references, and POCs where available.