oss-sec mailing list archives
CVE-2026-52691: Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module
From: Arnout Engelen <engelen () apache org>
Date: Fri, 04 Sep 2026 12:56:30 +0000
Severity: moderate
Affected versions:
- Apache Griffin Hive Metastore Module (org.apache.griffin:service): all versions
Description:
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
vulnerability in Apache Griffin Hive Metastore Module.
This issue affects Apache Griffin Hive Metastore Module: all versions.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an
alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Credit:
Firebasky ( https://github.com/firebasky ) (finder)
References:
https://attic.apache.org/projects/griffin.html
https://www.cve.org/CVERecord?id=CVE-2026-52691
Current thread:
- CVE-2026-52691: Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module Arnout Engelen (Sep 04)
