CLEANSTART-2026-JU40621

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-JU40621.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-JU40621
Upstream
Published
2026-10-08T00:55:31Z
Modified
2026-10-08T16:47:08Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container
Details

Security vulnerability affects the apache-hive package. An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container.

References

Affected packages

CleanStart / apache-hive

Package

Name
apache-hive
Purl
pkg:apk/cleanstart/apache-hive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-r3

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-JU40621.json"