Skip to content
Apache HiveGHSA-6hqr-c69m-r76q

Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore

High8.3CVE-2022-41137 · Published Dec 5, 2024

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. In real deployments, the vulnerability can be exploited only by authenticated users/clients that were able to successfully establish a connection to the Metastore. From an API perspective any code that calls the unsafe method may be vulnerable unless it performs additional prerechecks on the input arguments.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.hive:hive-exec
Maven
>= 4.0.0-alpha-1, < 4.0.0-alpha-24.0.0-alpha-2
Details and references

More Apache Hive advisories

All Apache Hive
Advisory
Apache Hive Incorrectly Assigns Permissions for a Critical Resource
Medium5.5Jan 29, 2025
Improper Authentication in org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
High7.3Mar 14, 2019
Apache Hive: improper certificate validation
High7.5Mar 14, 2019
Apache Hive: information disclosure
Medium4.3Mar 14, 2019
Improper Authentication in hive:hive-exec
High8.1Nov 21, 2018
Exposure of Sensitive Information to an Unauthorized Actor in Apache hive
Low3.7Nov 21, 2018

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.