SQL Injection Vulnerability in Apache Hive Metastore Server
CVE-2025-62728
What is CVE-2025-62728?
A SQL injection vulnerability exists in the Hive Metastore Server (HMS) when handling delete column statistics requests via Thrift APIs. This issue requires exploitation by trusted or authorized users, as direct access to Thrift APIs is typically restricted to specific applications like Hiveserver2. In most deployments, the HMS is protected from misuse due to limited access controls. However, users are advised to upgrade to version 4.2.0 to patch this security flaw. For those unable to update, setting the metastore.try.direct.sql property to false can mitigate potential exposure if the HMS Thrift APIs are accessible externally.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Hive 4.1.0 < 4.2.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved