Apache Hive Vulnerable to Code Injection Attacks
CVE-2023-35701
Summary
An issue within the Apache Hive JDBC driver introduces a vulnerability that can lead to arbitrary code execution on the host machine running the driver. This vulnerability occurs when a malicious user, having the necessary permissions, crafts a malicious JDBC URL that points to a compromised HTTP server. Upon attempting to establish a JDBC connection, the server responds with a specially crafted payload capable of executing arbitrary commands within the client process, particularly if it operates with elevated privileges. The vulnerability affects versions prior to 4.0.0 of Apache Hive. Immediate upgrade to the patched version is strongly advised to mitigate potential threats.
Affected Version(s)
Apache Hive 4.0.0-alpha-1 < 4.0.0
References
Timeline
Vulnerability published
Vulnerability Reserved