SQL Injection Vulnerability in Apache Hive Metastore Server
CVE-2025-62728
Currently unrated
What is CVE-2025-62728?
A SQL injection vulnerability exists in the Hive Metastore Server (HMS) when handling delete column statistics requests via Thrift APIs. This issue requires exploitation by trusted or authorized users, as direct access to Thrift APIs is typically restricted to specific applications like Hiveserver2. In most deployments, the HMS is protected from misuse due to limited access controls. However, users are advised to upgrade to version 4.2.0 to patch this security flaw. For those unable to update, setting the metastore.try.direct.sql property to false can mitigate potential exposure if the HMS Thrift APIs are accessible externally.
Affected Version(s)
Apache Hive 4.1.0 < 4.2.0