Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Hive
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-21234 2 Apache, Jodd 2 Hive, Jodd 2021-08-11 7.5 HIGH 9.8 CRITICAL
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
CVE-2018-1282 1 Apache 1 Hive 2018-05-15 7.5 HIGH 9.1 CRITICAL
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.