CVE-2018-21234 in Hive 3.1.3, should upgrade to 4.0.0
Open
- Dominant language
- Java
- Stars
- 2k
- Forks
- 990
- Avg merge
- 1d 8h
- Merged PRs (30d)
- 5
Description
**Describe the bug**
[CVE-2018-21234](https://nvd.nist.gov/vuln/detail/CVE-2018-21234) in Hive 3.1.2
**To Reproduce**
See also https://issues.apache.org/jira/browse/HIVE-25054
**Expected behavior**
Upgrade to Hive 4.0.0
Contributor guide
No contributing guide indexed for this repository
Research direction
Review the CVE-2018-21234 report and the linked HIVE-25054 issue first, then locate where Apache Drill pins or integrates Hive 3.1.x. Assess the compatibility impact of upgrading to Hive 4.0.0 and run the relevant project tests; done means the vulnerable Hive version is no longer used and the build remains passing.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- hadoop, java
- Domain
- backend, databases, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100