CVE-2018-1282
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 5.5%
exploitation probability
5.5%top 8% of all CVEs
observed exploitation
nono source reports it
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
Affected products
Apache Software Foundation · Apache Hive