📦 Hive

by Apache

🔍 What is Hive?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-41137

HIGH CVSS 8.3 Dec 5, 2024

This vulnerability in Apache Hive Metastore allows authenticated users to achieve remote code execution by exploiting unsafe deserialization in partition filtering operations. Only authenticated clien...

CVE-2021-34538

HIGH CVSS 7.5 Jul 16, 2022

This vulnerability in Apache Hive allows unauthorized users to manipulate existing User-Defined Functions (UDFs) without proper authorization checks. Attackers can drop and recreate UDFs to point to m...

CVE-2025-62728

MEDIUM CVSS 5.4 Nov 26, 2025

This SQL injection vulnerability in Apache Hive Metastore Server allows authorized users to execute arbitrary SQL commands when calling Thrift APIs to delete column statistics. It affects Hive version...

CVE-2024-23945

MEDIUM CVSS 5.9 Dec 23, 2024

Apache Hive and Spark expose correct cookie signatures during signature mismatch errors, potentially allowing attackers to forge valid signed cookies. This affects systems using Hive service or Spark ...

CVE-2023-35701

MEDIUM CVSS 6.6 May 3, 2024

This CVE describes a code injection vulnerability in Apache Hive's JDBC driver that allows arbitrary code execution on client systems. Attackers can exploit it by tricking users into connecting to mal...