GHSA-jmf4-pq78-f8vj
GitHub Security Advisory
Moderate severity vulnerability that affects org.apache.hive:hive-jdbc
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.
Affected Packages
Maven
org.apache.hive:hive-jdbc
Affected versions:
0
(fixed in 2.3.4)
Maven
org.apache.hive:hive-jdbc
Affected versions:
3.0.0
(fixed in 3.1.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 16, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.