Description
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
Remediation
References
http://www.securityfocus.com/bid/103751
https://lists.apache.org/thread.html/74bd2bff1827febb348dfb323986fa340d3bb97a315ab93c3ccc8299%40%3Cdev.hive.apache.org%3E
https://exchange.xforce.ibmcloud.com/vulnerabilities/141253
Related Vulnerabilities
CVE-2021-3629 Vulnerability in maven package io.undertow:undertow-core
CVE-2022-24697 Vulnerability in maven package org.apache.kylin:kylin-server-base
CVE-2022-28366 Vulnerability in maven package net.sourceforge.htmlunit:neko-htmlunit
CVE-2018-1271 Vulnerability in maven package org.springframework:spring-webmvc
CVE-2020-9483 Vulnerability in maven package org.apache.skywalking:server-storage-plugin