CVE-2022-41137

Source
https://cve.org/CVERecord?id=CVE-2022-41137
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41137.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-41137
Aliases
Published
2024-12-05T10:01:41Z
Modified
2026-08-12T13:33:19Z
Severity
  • 8.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H CVSS Calculator
Summary
Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore
Details

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data.

In real deployments, the vulnerability can be exploited only by authenticated users/clients that were able to successfully establish a connection to the Metastore. From an API perspective any code that calls the unsafe method may be vulnerable unless it performs additional prerechecks on the input arguments.

Database specific
{
    "cna_assigner":  "apache",
    "cwe_ids":  [
        "CWE-502"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41137.json"
}
References

Affected packages

Git / github.com/apache/hive

Affected ranges

Type
GIT
Repo
https://github.com/apache/hive
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "4.0.0-alpha-1"
        },
        {
            "fixed":  "4.0.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41137.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "176252969647808819018956217042418030054",
                "148765723542959021775041479029359294166",
                "109646971673034884526254632607416440396",
                "96777492195815811987895310964170001917",
                "275610775353484647010641099073039938116",
                "186784018516718734145129976931224401193",
                "91040751201010041843362994917424120478",
                "203315196876360469223612076598856915083",
                "297726764222781860821609643520331694883",
                "93185151900701281387028188233629952707",
                "156554147834937369276481875105126795013",
                "331202356562580726519232815468518700730",
                "254172917600993851173986950264644358540",
                "193401062204728262232018650555070648923",
                "200633276573483699658064295815442173545"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2022-41137-0ce99ac7",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/apache/hive/commit/60027bb9c91a93affcfebd9068f064bc1f2a74c9",
        "target":  {
            "file":  "ql/src/test/org/apache/hadoop/hive/ql/exec/TestSerializationUtilities.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "263856913626910905354104002981922829013",
                "162790852404277127451425496830849228309",
                "67889690432705714173763375026543483726",
                "18856704957606996723303946333703388103",
                "177172567606494834083022104241806423403",
                "234926539788456250129929320541185100527",
                "326348501204951253055819365028006683721",
                "89674929784629085464548469844115393022",
                "215212851182668798429202669811327828698",
                "234007931132895321726276308777948418358",
                "339964719829410395527165794888369619804",
                "120207412203677137346631569470792912868",
                "153265536178319850165435216646959288526",
                "309222956129500248050813712786945129372",
                "186957300040246786784082552195084652150",
                "205766724276707331664954489763609523545",
                "313807341291995520109622741102043546588",
                "249215863235046194667201175805486663559"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2022-41137-0fc6087f",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/apache/hive/commit/60027bb9c91a93affcfebd9068f064bc1f2a74c9",
        "target":  {
            "file":  "standalone-metastore/metastore-server/src/main/java/org/apache/hadoop/hive/metastore/ObjectStore.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "29621208303472556323039160039525316033",
            "length":  387
        },
        "id":  "CVE-2022-41137-385e3345",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/apache/hive/commit/60027bb9c91a93affcfebd9068f064bc1f2a74c9",
        "target":  {
            "file":  "ql/src/java/org/apache/hadoop/hive/ql/optimizer/ppr/PartitionExpressionForMetastore.java",
            "function":  "deserializeExpr"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "125137454714460466793633556305816281759",
            "length":  452
        },
        "id":  "CVE-2022-41137-3dbe38c8",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/apache/hive/commit/60027bb9c91a93affcfebd9068f064bc1f2a74c9",
        "target":  {
            "file":  "standalone-metastore/metastore-server/src/main/java/org/apache/hadoop/hive/metastore/ObjectStore.java",
            "function":  "createExpressionProxy"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "54160317792387969614035647418100657180",
                "296746150790626136187213312726909145619",
                "133479562210225632537696404987514320452",
                "172994094651553346583643203842836212636",
                "246513948614157673739246114564643926902",
                "263005736405376511539136982027209196512",
                "57183021538823422327191810049997480919",
                "202447139807854788175261452009892502475"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2022-41137-471b9278",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/apache/hive/commit/60027bb9c91a93affcfebd9068f064bc1f2a74c9",
        "target":  {
            "file":  "ql/src/java/org/apache/hadoop/hive/ql/optimizer/ppr/PartitionExpressionForMetastore.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "327778368396670354291282487749421437126",
            "length":  133
        },
        "id":  "CVE-2022-41137-5bb23cd3",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/apache/hive/commit/60027bb9c91a93affcfebd9068f064bc1f2a74c9",
        "target":  {
            "file":  "ql/src/java/org/apache/hadoop/hive/ql/exec/SerializationUtilities.java",
            "function":  "releaseKryo"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "56697521908859849453345942894901448451",
            "length":  201
        },
        "id":  "CVE-2022-41137-871cf77f",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/apache/hive/commit/60027bb9c91a93affcfebd9068f064bc1f2a74c9",
        "target":  {
            "file":  "ql/src/java/org/apache/hadoop/hive/ql/exec/SerializationUtilities.java",
            "function":  "deserializeObjectWithTypeInformation"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "58445830554887856220949734530226159065",
            "length":  890
        },
        "id":  "CVE-2022-41137-b24dcd9c",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/apache/hive/commit/60027bb9c91a93affcfebd9068f064bc1f2a74c9",
        "target":  {
            "file":  "standalone-metastore/metastore-server/src/main/java/org/apache/hadoop/hive/metastore/ObjectStore.java",
            "function":  "initialize"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "239125987013368652811930601419083416938",
                "3095297029928773302791831827849429650",
                "104793357801422377043062502024091782850",
                "194938387532650857879923975758710379764",
                "209305229933614050655028363085689596044",
                "76498419413052270791357166651162051998",
                "227180716914888642545709711978451084886",
                "133501533758232873726091027015031643550",
                "38483496538749636820237160168650857287",
                "226710315466895972320058996717086031143",
                "25773735487705901914145650110757454270",
                "13370894027188427751760949226928666250",
                "284979136164576521226654585713305606734",
                "51630398157720103564879958393021497954",
                "261267976775995942958934979224649310236",
                "36521724375749627793096775629357696308",
                "177118579829607480453942225514121444691"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2022-41137-c62f2824",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/apache/hive/commit/60027bb9c91a93affcfebd9068f064bc1f2a74c9",
        "target":  {
            "file":  "ql/src/java/org/apache/hadoop/hive/ql/exec/SerializationUtilities.java"
        }
    }
]
vanir_signatures_modified
"2026-08-12T13:33:19Z"