GHSA-932v-x9x2-vq29
HIGHCVE-2025-62728SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/authorized users/applications that are allowed to call directly the Thrift APIs. In most real-world deployments, HMS is accessible to only a handful of applications (e.g., Hiveserver2) thus the vulnerability is not exploi
- Affected
- >= 4.1.0, < 4.2.0
- Fixed in
- 4.2.0
- Weakness
- CWE-89
- Published
- 2025-11-26
- Source
- github