oss-sec mailing list archives

CVE-2026-52691: Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module


From: Arnout Engelen <engelen () apache org>
Date: Fri, 04 Sep 2026 12:56:30 +0000

Severity: moderate 

Affected versions:

- Apache Griffin Hive Metastore Module (org.apache.griffin:service): all versions

Description:

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 
vulnerability in Apache Griffin Hive Metastore Module. 



This issue affects Apache Griffin Hive Metastore Module: all versions.



As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an 
alternative or restrict access to the instance to trusted users.



NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Credit:

Firebasky ( https://github.com/firebasky ) (finder)

References:

https://attic.apache.org/projects/griffin.html
https://www.cve.org/CVERecord?id=CVE-2026-52691


Current thread: