CVE-2018-1282: Apache Hive

Critical severity, CVSS 9.1. EPSS: 5.5% chance of exploitation in the next 30 days.

This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.

Affected products

  • Apache Hive: from 0.7.1, up to and including 2.3.2

Published 2018-04-05. Last modified 2026-06-17.