SQL Injection Vulnerability in Apache Hive JDBC Driver
CVE-2018-1282
9.1CRITICAL
Summary
The vulnerability present in the Apache Hive JDBC driver, ranging from versions 0.7.1 to 2.3.2, allows attackers to execute SQL injection attacks. This occurs when input parameters are not properly sanitized, thereby permitting crafted arguments to bypass the JDBC driver's argument escaping mechanisms in the PreparedStatement implementation. As a result, malicious users can manipulate database queries, posing significant security risks to applications dependent on this driver.
Affected Version(s)
Apache Hive 0.7.1 to 2.3.2
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved