SCA: security update for org.apache.hive:hive-jdbc (GHSA-vpw3-3prf-3974)

medium Tenable Self-Hosted Container Security Plugin ID 419477

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability
affects the Hive JDBC driver component and it can potentially lead to arbitrary code execution on the
machine/endpoint that the JDBC driver (client) is running. The malicious user must have sufficient
permissions to specify/edit JDBC URL(s) in an endpoint relying on the Hive JDBC driver and the JDBC client
process must run under a privileged user to fully exploit the vulnerability. The attacker can setup a
malicious HTTP server and specify a JDBC URL pointing towards this server. When a JDBC connection is
attempted, the malicious HTTP server can provide a special response with customized payload that can
trigger the execution of certain commands in the JDBC client.This issue affects Apache Hive: from
4.0.0-alpha-1 before 4.0.0. Users are recommended to upgrade to version 4.0.0, which fixes the issue.
(CVE-2023-35701)

See Also

https://github.com/advisories/GHSA-vpw3-3prf-3974

Plugin Details

Severity: Medium

ID: 419477

Version: Revision 1.19

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.76

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:H/Au:M/C:C/I:C/A:C

CVSS Score Source: CVE-2023-35701

CVSS v3

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 5.8

Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/3/2024

Vulnerability Publication Date: 5/3/2024

Reference Information

CVE: CVE-2023-35701

cwe: CWE-94