HIGH8.3CVE-2022-41137Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore >= 4.0.0-alpha-1, < 4.0.0-alpha-2
HIGH8.3CVE-2015-7521High severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service >= 1.0.0, < 1.2.2
>= 3.0.0, < 3.1.1
HIGH7.5org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service vulnerable to Improper Certificate Validation
from 0, < 1.2.2
HIGH7.3Improper Authentication in org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
>= 1.0.0, < 1.0.1
MEDIUM5.5Apache Hive Incorrectly Assigns Permissions for a Critical Resource
from 0, < 4.0.1
MEDIUM4.3Moderate severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
>= 2.1.0, < 2.1.2
LOW3.7Exposure of Sensitive Information to an Unauthorized Actor in Apache hive
>= 0.6.0, < 2.3.3
LOW3.7Incorrect Permission Assignment for Critical Resource in Apache hive
>= 2.1.0, < 2.3.3
—Low severity vulnerability that affects org.apache.hive:hive-exec, org.apache.hive:hive, and org.apache.hive:hive-service
from 0, < 0.13.1