apache / apache/drill

CVE-2018-21234 in Hive 3.1.3, should upgrade to 4.0.0

Open
#2,294 3 comments 1 reaction 0 assignees View on GitHub
Dominant language
Java
Stars
2k
Forks
990
Avg merge
1d 8h
Merged PRs (30d)
5

Description

**Describe the bug**
[CVE-2018-21234](https://nvd.nist.gov/vuln/detail/CVE-2018-21234) in Hive 3.1.2

**To Reproduce**
See also https://issues.apache.org/jira/browse/HIVE-25054

**Expected behavior**
Upgrade to Hive 4.0.0

Contributor guide

No contributing guide indexed for this repository

Research direction

Review the CVE-2018-21234 report and the linked HIVE-25054 issue first, then locate where Apache Drill pins or integrates Hive 3.1.x. Assess the compatibility impact of upgrading to Hive 4.0.0 and run the relevant project tests; done means the vulnerable Hive version is no longer used and the build remains passing.

Written by the indexing model from the issue text.

Assessment

Tech stack
hadoop, java
Domain
backend, databases, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.