CVE-2018-21234: Apache Hive

Critical severity, CVSS 9.8. EPSS: 8.3% chance of exploitation in the next 30 days.

Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.

Affected products

  • Apache Hive: version 3.1.2 only
  • Jodd Jodd: before 5.0.4 (fixed in 5.0.4)

Published 2020-05-21. Last modified 2026-06-17.