Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-41137

Опубликовано: 05 дек. 2024
Источник: nvd
CVSS3: 8.3
EPSS Низкий

Описание

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data.

In real deployments, the vulnerability can be exploited only by authenticated users/clients that were able to successfully establish a connection to the Metastore. From an API perspective any code that calls the unsafe method may be vulnerable unless it performs additional prerechecks on the input arguments.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:hive:4.0.0:alpha1:*:*:*:*:*:*

EPSS

Процентиль: 92%
0.09175
Низкий

8.3 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.3
redhat
около 1 года назад

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. In real deployments, the vulnerability can be exploited only by authenticated users/clients that were able to successfully establish a connection to the Metastore. From an API perspective any code that calls the unsafe method may be vulnerable unless it performs additional prerechecks on the input arguments.

CVSS3: 8.3
github
около 1 года назад

Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore

EPSS

Процентиль: 92%
0.09175
Низкий

8.3 High

CVSS3

Дефекты

CWE-502