Apache hive
This hub aggregates every CVE we track for Apache hive, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
1
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM8HIGH4LOW2CRITICAL1
Monthly trend
0
0
0
2
2
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache hive.
- CVE-2025-62728Apache Hive: SQL injection vulnerability when processing delete column statistics requests via the HMS Thrift APIs5.4
- CVE-2024-29869Apache Hive: Credentials file created with non restrictive permissions5.5
- CVE-2024-23953Apache Hive: Timing Attack Against Signature in LLAP util6.5
- CVE-2024-23945Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails5.9
- CVE-2022-41137Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore8.3
- CVE-2023-35701Apache Hive: Arbitrary command execution via JDBC driver6.6
- CVE-2021-34538Apache Hive Security vulnerability in Hive with UDFs7.5
- CVE-2020-1926Timing attack in Cookie signature verification5.9
- CVE-2018-11777In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.8.1
- CVE-2018-1314In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary tabl...4.3
- CVE-2018-1284In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the conten...3.7
- CVE-2018-1315In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statement is run using HPL/SQL extension to Hive, a compromised/malicious FTP server can cause the file to be written to an arbitrary location on...3.7
- CVE-2018-1282This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement impleme...9.1
- CVE-2017-12625Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a vi...4.3
- CVE-2016-3083Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificate during the connection setup, the cli...7.5
Product normalization is registry-driven with AI assist and human review. How it works