[I] CVE-2018-21234 in Hive 3.1.2, should upgrade to 4.0.0 (drill)

2023-03-12 Thread via GitHub
ssainz opened a new issue, #2294: URL: https://github.com/apache/drill/issues/2294 **Describe the bug** [CVE-2018-21234](https://nvd.nist.gov/vuln/detail/CVE-2018-21234) in Hive 3.1.2 **To Reproduce** See also https://issues.apache.org/jira/browse/HIVE-25054 **Expected

Re: [I] CVE-2018-21234 in Hive 3.1.2, should upgrade to 4.0.0 (drill)

2023-03-12 Thread via GitHub
jnturton commented on issue #2294: URL: https://github.com/apache/drill/issues/2294#issuecomment-1465518201 Ah, thanks. I guess we'll have to wait for a bug fix release or the release of 4.0.0 then. -- This is an automated message from the Apache Git Service. To respond to the message,

Re: [I] CVE-2018-21234 in Hive 3.1.2, should upgrade to 4.0.0 (drill)

2023-03-12 Thread via GitHub
ssainz commented on issue #2294: URL: https://github.com/apache/drill/issues/2294#issuecomment-1465408956 Hello @jnturton , Hive 3.1.3 is vulnerable to [CVE-2018-21234](https://nvd.nist.gov/vuln/detail/CVE-2018-21234). Please see the [pom.xml of Hive