This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
{
"nvd_published_at": null,
"github_reviewed_at": "2020-06-16T21:43:10Z",
"severity": "CRITICAL",
"cwe_ids": [
"CWE-89"
],
"github_reviewed": true
}