The Apache Hive team is proud to announce the release of Apache Hive version 4.2.1.
This bugfix release addresses three security vulnerabilities: - HIVE-29622: Potential vulnerability in HiveMetaStore partition-name direct-SQL paths - HIVE-29653: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation - HIVE-29671: SSRF in Avro SerDe via avro.schema.url *Users running Apache Hive 4.2.0 are encouraged to upgrade to 4.2.1*. The Apache Hive (TM) data warehouse software facilitates querying and managing large datasets residing in distributed storage. Built on top of Apache Hadoop (TM), it provides, among others: - Tools to enable easy data extract/transform/load (ETL) - A mechanism to impose structure on a variety of data formats - Access to files stored either directly in Apache HDFS (TM) or in other data storage systems such as Apache HBase (TM) - Massively parallel query execution via Apache Tez For Hive release details and downloads, please visit: https://hive.apache.org/downloads.html Hive 4.2.1 Release Notes are available here: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310843&version=12357270 For the Docker image, check: https://hub.docker.com/r/apache/hive/tags We would like to thank the many contributors who made this release possible. Regards, The Apache Hive Team
