GHSA-jf2m-435m-mxw8
CRITICALCVE-2018-1282This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
- Affected
- >= 0.7.1, < 2.3.3
- Fixed in
- 2.3.3
- Weakness
- CWE-89
- Published
- 2018-11-21
- Source
- github