Loading HuntDB...

GHSA-jmf4-pq78-f8vj

GitHub Security Advisory

Moderate severity vulnerability that affects org.apache.hive:hive-jdbc

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.

Affected Packages

Maven org.apache.hive:hive-jdbc
Affected versions: 0 (fixed in 2.3.4)
Maven org.apache.hive:hive-jdbc
Affected versions: 3.0.0 (fixed in 3.1.1)

Related CVEs

Key Information

GHSA ID
GHSA-jmf4-pq78-f8vj
Published
November 21, 2018 10:24 PM
Last Modified
September 14, 2021 7:47 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.apache.hive:hive-jdbc
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 16, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.