« Volver al listado

CVE-2022-41137

Estado: AnalizadaAlta (8.3)—

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data.

In real deployments, the vulnerability can be exploited only by authenticated users/clients that were able to successfully establish a connection to the Metastore. From an API perspective any code that calls the unsafe method may be vulnerable unless it performs additional prerechecks on the input arguments.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad remota en Apache Hive Metastore que requiere autenticación previa (PR:L) y permite RCE mediante deserialización insegura (CWE-502). T1210 por red con privilegios; impactos: ejecución arbitraria de código (T1059) y potencial escalada a nivel de sistema (T1068).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-41137",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-41137",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-05T17:00:40.730056Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache Hive",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.0-alpha-1",
              "lessThan": "4.0.0",
              "versionType": "semver"
            }
          ],
          "packageName": "org.apache.hive:hive-exec",
          "collectionURL": "https://repo.maven.apache.org/maven2",
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:apache:hive:*:*:*:*:*:*:*:*"
          ],
          "vendor": "apache",
          "product": "hive",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.0-alpha-1",
              "lessThan": "4.0.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-12-05T10:15:04.450",
  "references": [
    {
      "url": "https://github.com/apache/hive",
      "tags": [
        "Product"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://github.com/apache/hive/commit/60027bb9c91a93affcfebd9068f064bc1f2a74c9",
      "tags": [
        "Patch"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://issues.apache.org/jira/browse/HIVE-26539",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread/jwtr3d9yovf2wo0qlxvkhoxnwxxyzgts",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/12/04/2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data.\n\nIn real deployments, the vulnerability can be exploited only by authenticated users/clients that were able to successfully establish a connection to the Metastore. From an API perspective any code that calls the unsafe method may be vulnerable unless it performs additional prerechecks on the input arguments."
    },
    {
      "lang": "es",
      "value": "Apache Hive Metastore (HMS) utiliza el método SerializationUtilities#deserializeObjectWithTypeInformation al filtrar y obtener particiones, lo que no es seguro y puede provocar una ejecución de código remoto (RCE), ya que permite la deserialización de datos arbitrarios. En implementaciones reales, la vulnerabilidad solo puede ser explotada por usuarios o clientes autenticados que pudieron establecer una conexión exitosa con Metastore. Desde una perspectiva de API, cualquier código que llame al método no seguro puede ser vulnerable a menos que realice comprobaciones previas adicionales en los argumentos de entrada."
    }
  ],
  "lastModified": "2026-06-17T05:02:39.887",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:hive:4.0.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76721527-FDE1-4313-A7BB-7324CEC18C08"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}