Hive

Vendor:

First CVE: Nov 16, 2014 · Active for 11 years

20
Total CVEs
More Total CVEs than 94% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Hive over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2014
11 years ago
Most Recent CVE
Nov 26, 2025
240 days ago

CVE Severity & Scoring

Hive20 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (5.0%)
Network18 (90.0%)
Unknown1 (5.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (70.0%)
High5 (25.0%)
Unknown1 (5.0%)
User Interaction
None19 (95.0%)
Unknown1 (5.0%)
Required0 (0.0%)
Privileges Required
Low7 (35.0%)
High1 (5.0%)
None11 (55.0%)
Unknown1 (5.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
May 21, 20209.834NONO
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in Prepared
Apr 5, 20189.131NONO
In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is n
Nov 8, 20188.127NONO
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, misha
Dec 21, 20157.327NONO
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
Feb 12, 20217.525NONO
Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificate during the connecti
May 30, 20177.525NONO
Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Cod
Dec 5, 20248.323NONO
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass inte
Jan 29, 20168.323NONO
SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/a
Nov 26, 20255.421NONO
Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by byte. The attacker
Jan 28, 20256.521NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Hive

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.1.015.40.3%00
4.0.027.01.2%00
3.1.219.88.3%00
2.3.014.31.4%00
2.2.014.31.4%00
2.1.114.31.4%00
2.1.014.31.4%00
1.2.127.93.6%00
1.2.027.93.6%00
1.1.117.51.0%00
1.1.037.74.7%00
1.0.127.93.6%00
1.0.037.74.7%00
0.14.017.51.0%00
0.13.117.51.0%00
0.13.017.51.0%00