Impact
Apache Griffin Hive Metastore Module suffers from an SQL injection flaw caused by improper neutralization of special elements in SQL commands. The weakness can allow an attacker to craft malicious input that is executed directly against the database, leading to unauthorized data disclosure, modification, or deletion. The CWE classification is 89. Because the project is retired and no patch is forthcoming, the vulnerability remains fully exploitable for all released versions.
Affected Systems
Both the Apache Griffin Hive Metastore Module and its dependent systems are affected. All versions released under the Apache Software Foundation fall into this scope. No specific minor or major releases are singled out; the issue applies broadly to the whole module.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the risk remains high due to the lack of a vendor fix and a CVSS score of 8.8. The likely attack vector is an unauthenticated or authenticated user who can submit queries to the metastore through exposed interfaces such as REST or command‑line utilities. Inference based on typical usage patterns suggests that an attacker could remotely inject SQL if the metastore is reachable from untrusted networks. The severity is significant, as successful exploitation can compromise data integrity and confidentiality.
OpenCVE Enrichment