SQL Injection in hive-jdbc
Critical severity
GitHub Reviewed
Published
Nov 21, 2018
to the GitHub Advisory Database
•
Updated Apr 19, 2024
Package
Affected versions
>= 0.7.1, < 2.3.3
Patched versions
2.3.3
Description
Published to the GitHub Advisory Database
Nov 21, 2018
Reviewed
Jun 16, 2020
Last updated
Apr 19, 2024
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
References