CVE-2026-52691: Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module
UNSUPPORTED WHEN ASSIGNED Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module.
This issue affects Apache Griffin Hive Metastore Module: all versions.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the Apache Griffin Hive Metastore Module instance to trusted users only (since this SQL Injection affects all versions and no fixed version will be released).
Event History
Frequently Asked Questions
Is a fix expected for affected deployments?
No. The project is retired, and no fixed release is planned; all versions are affected.
What should organizations do if they still use this module?
Migrate to an alternative where possible. If immediate replacement is not feasible, restrict instance access to trusted users.