Uploaded image for project: 'Hive'
  1. Hive
  2. HIVE-24787

Hive - upgrade log4j 2.12.1 to 2.13.2+ due to CVE-2020-9488

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 2.4.0, 3.1.2
    • HiveServer2
    • None

    Description

      Hive is pulling in log4j 2.12.1 specifically to:

      • ./usr/lib/hive/lib/log4j-core-2.12.1.jar

      CVE-2020-9488 affects this version and the fix is to upgrade to 2.13.2+. So, upgrade this dependency.

      Attachments

        Issue Links

          Activity

            People

              RevivalVape Revival Vape
              RevivalVape Revival Vape
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: