Apache Hive Vulnerable to Code Injection Attacks
CVE-2023-35701

6.6MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
3 May 2024

Summary

An issue within the Apache Hive JDBC driver introduces a vulnerability that can lead to arbitrary code execution on the host machine running the driver. This vulnerability occurs when a malicious user, having the necessary permissions, crafts a malicious JDBC URL that points to a compromised HTTP server. Upon attempting to establish a JDBC connection, the server responds with a specially crafted payload capable of executing arbitrary commands within the client process, particularly if it operates with elevated privileges. The vulnerability affects versions prior to 4.0.0 of Apache Hive. Immediate upgrade to the patched version is strongly advised to mitigate potential threats.

Affected Version(s)

Apache Hive 4.0.0-alpha-1 < 4.0.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kostya Kortchinsky
.