Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.apache.hive/hive-common
  4. ›
  5. CVE-2025-62728

CVE-2025-62728: Hive Metastore Server is vulnerable to SQL Injection

November 26, 2025 (updated December 1, 2025)

SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/authorized users/applications that are allowed to call directly the Thrift APIs. In most real-world deployments, HMS is accessible to only a handful of applications (e.g., Hiveserver2) thus the vulnerability is not exploitable. Moreover, the vulnerable code cannot be reached when metastore.try.direct.sql property is set to false.

This issue affects Apache Hive: from 4.1.0 before 4.2.0.

Users are recommended to upgrade to version 4.2.0, which fixes the issue. Users who cannot upgrade directly are encouraged to set metastore.try.direct.sql property to false if the HMS Thrift APIs are exposed to general public.

References

  • github.com/advisories/GHSA-932v-x9x2-vq29
  • github.com/apache/hive
  • github.com/apache/hive/commit/c18d0df2702130cf5d0f050e516eb8999aa56301
  • issues.apache.org/jira/browse/HIVE-29269
  • lists.apache.org/thread/yj65dd8dmzgy8p3nv8zy33v8knzg9o7g
  • nvd.nist.gov/vuln/detail/CVE-2025-62728

Code Behaviors & Features

Detect and mitigate CVE-2025-62728 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 4.1.0 before 4.2.0

Fixed versions

  • 4.2.0

Solution

Upgrade to version 4.2.0 or above.

Impact 8.1 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Source file

maven/org.apache.hive/hive-common/CVE-2025-62728.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 14 Dec 2025 00:18:45 +0000.