Apache Hive Vulnerable to Code Injection Attacks
CVE-2023-35701

Currently unrated

Key Information:

Vendor
Apache
Vendor
CVE Published:
3 May 2024

Summary

An issue within the Apache Hive JDBC driver introduces a vulnerability that can lead to arbitrary code execution on the host machine running the driver. This vulnerability occurs when a malicious user, having the necessary permissions, crafts a malicious JDBC URL that points to a compromised HTTP server. Upon attempting to establish a JDBC connection, the server responds with a specially crafted payload capable of executing arbitrary commands within the client process, particularly if it operates with elevated privileges. The vulnerability affects versions prior to 4.0.0 of Apache Hive. Immediate upgrade to the patched version is strongly advised to mitigate potential threats.

Affected Version(s)

Apache Hive 4.0.0-alpha-1 < 4.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kostya Kortchinsky
.