Vulnerabilities
Vulnerable Software
Apache:  >> Hive  >> 2.2.0  Security Vulnerabilities
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
CVSS Score
9.1
EPSS Score
0.003
Published
2018-04-05
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcement does not happen correctly on the table for masked columns.
CVSS Score
4.3
EPSS Score
0.005
Published
2017-11-01


Contact Us

Shodan ® - All rights reserved