Bypassing Argument Escaping/Cleanup in Apache Hive JDBC Driver

Bypassing Argument Escaping/Cleanup in Apache Hive JDBC Driver

CVE-2018-1282 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.

Learn more about our Cis Benchmark Audit For Apache Http Server.