Skip to content

Apache Hive security advisories

10 advisories · none critical or high in 12 months · latest Jan 29, 2025

10 advisories

DateAdvisory
Jan 292025Apache Hive Incorrectly Assigns Permissions for a Critical Resource
CVE-2024-29869Medium5.5fixed in 4.0.1
Dec 52024Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore
CVE-2022-41137High8.3fixed in 4.0.0-alpha-2
Mar 142019Improper Authentication in org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
CVE-2015-1772High7.3fixed in 1.0.1, 1.1.1
Mar 142019org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service vulnerable to Improper Certificate Validation
CVE-2016-3083High7.5fixed in 1.2.2, 2.0.1
Mar 142019Moderate severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
CVE-2017-12625Medium4.3fixed in 2.1.2, 2.2.1, 2.3.1
Nov 212018Improper Authentication in hive:hive-exec
CVE-2018-11777High8.1fixed in 2.3.4, 3.1.1
Nov 212018Exposure of Sensitive Information to an Unauthorized Actor in Apache hive
CVE-2018-1284Low3.7fixed in 2.3.3
Nov 212018Incorrect Permission Assignment for Critical Resource in Apache hive
CVE-2018-1315Low3.7fixed in 2.3.3
Nov 212018High severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
CVE-2015-7521High8.3fixed in 1.2.2
Nov 212018Low severity vulnerability that affects org.apache.hive:hive-exec, org.apache.hive:hive, and org.apache.hive:hive-service
CVE-2014-0228Lowfixed in 0.13.1
About Apache Hive

The SQL data warehouse on Hadoop.

Packages watched: org.apache.hive:hive-exec (Maven).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.