CVE-2018-1282
published 2018-04-05CVE-2018-1282: This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC…
PriorityP350critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EPSS
5.52%
91.9th percentile
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hive | 0.7.1 – 2.3.2 | — |
| apache_software_foundation | apache_hive | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (Apache Hive) — CVE-2018-1282
vendor_oracle·2023-07-15·CVSS 9.1
CVE-2018-1282 [CRITICAL] Oracle Oracle Analytics Risk Matrix: Analytics Server (Apache Hive) — CVE-2018-1282
Oracle Oracle Analytics Risk Matrix: Analytics Server (Apache Hive) vulnerability
CVE: CVE-2018-1282
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Red Hat
hive: Improper input validation in jdbc/HivePreparedStatement.java allows for SQL injection
vendor_redhat·2018-02-23·CVSS 9.1
CVE-2018-1282 [CRITICAL] CWE-89 hive: Improper input validation in jdbc/HivePreparedStatement.java allows for SQL injection
hive: Improper input validation in jdbc/HivePreparedStatement.java allows for SQL injection
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
Package: hive (Red Hat JBoss Fuse Integration Service 2) - Not affected
GHSA
SQL Injection in hive-jdbc
ghsa·2018-11-21
CVE-2018-1282 [CRITICAL] CWE-89 SQL Injection in hive-jdbc
SQL Injection in hive-jdbc
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
OSV
SQL Injection in hive-jdbc
osv·2018-11-21
CVE-2018-1282 [CRITICAL] SQL Injection in hive-jdbc
SQL Injection in hive-jdbc
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1273 spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests
bugzilla·2018-04-11·CVSS 9.8
CVE-2018-1273 [CRITICAL] CVE-2018-1273 spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests
CVE-2018-1273 spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests
Spring Data Commons, versions 1.13 to 1.13.10 and 2.0 to 2.0.5, , contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data’s projection-based request payload binding hat can lead to a remote code execution attack.
External References:
https://pivotal.io/security/cve-2018-1273
Upstream Issue:
https://jira.spring.io/browse/DATACMNS-1282
Upstream Patches:
https://github.com/spring-projects/spring-data-commons/commit/b1a20ae1e82a63f99b3afc6f2
Bugzilla
CVE-2018-1282 hive: Improper input validation in jdbc/HivePreparedStatement.java allows for SQL injection
bugzilla·2018-04-06·CVSS 9.1
CVE-2018-1282 [CRITICAL] CVE-2018-1282 hive: Improper input validation in jdbc/HivePreparedStatement.java allows for SQL injection
CVE-2018-1282 hive: Improper input validation in jdbc/HivePreparedStatement.java allows for SQL injection
Apache Hive through version 2.3.2 is vulnerable to SQL injection in the JDBC driver due to improper input sanitization in jdbc/HivePreparedStatement.java.
External References:
https://lists.apache.org/thread.html/74bd2bff1827febb348dfb323986fa340d3bb97a315ab93c3ccc8299@%3Cdev.hive.apache.org%3E
Upstream Issue:
https://issues.apache.org/jira/browse/HIVE-18788
Upstream Patches:
https://issues.apache.org/jira/secure/attachment/12911779/HIVE-18788.1.patch
https://issues.apache.org/jira/secure/attachment/12911868/HIVE-18788.2.patch
https://issues.apache.org/jira/secure/attachment/12911921/HIVE-18788.3.patch
https://issues.apache.org/jira/secure/attachment/12912687/HIVE-18788.3-bra
Bugzilla
CVE-2018-1282 hive: Improper input validation in jdbc/HivePreparedStatement.java allows for SQL injection [fedora-all]
bugzilla·2018-04-06·CVSS 9.1
CVE-2018-1282 [CRITICAL] CVE-2018-1282 hive: Improper input validation in jdbc/HivePreparedStatement.java allows for SQL injection [fedora-all]
CVE-2018-1282 hive: Improper input validation in jdbc/HivePreparedStatement.java allows for SQL injection [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
http://www.securityfocus.com/bid/103751https://lists.apache.org/thread.html/74bd2bff1827febb348dfb323986fa340d3bb97a315ab93c3ccc8299%40%3Cdev.hive.apache.org%3Ehttps://exchange.xforce.ibmcloud.com/vulnerabilities/141253http://www.securityfocus.com/bid/103751https://lists.apache.org/thread.html/74bd2bff1827febb348dfb323986fa340d3bb97a315ab93c3ccc8299%40%3Cdev.hive.apache.org%3E
2018-04-05
Published