PT-2026-81256 · Apache · Apache Hive
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Hive versions prior to 4.2.1
Description
An authenticated remote attacker with CREATE TABLE privileges can execute a Server-Side Request Forgery (SSRF) during Avro SerDe schema resolution. By setting the
avro.schema.url table property on an Avro table, the attacker can force the Hive server to fetch a URL under their control when the table is queried. This can lead to the exposure of local server files, internal network services, or cloud instance metadata to the Hive process identity. The attack requires network access to HiveServer2 or the Metastore and valid authentication.Recommendations
Upgrade to version 4.2.1.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Hive