ZeroHour

CVE-2026-52691

niche

SQL Injection in Apache Griffin Hive Metastore Module (unsupported, no fix planned)

CVSS 3.1
8.8 high
EPSS
<1%p20
Published
()
Modified
AI analysis

The Apache Griffin Hive Metastore Module is vulnerable to SQL injection (CWE-89) caused by improper neutralization of special elements in SQL commands, affecting all versions of the product. An attacker with low privileges and network access to the module can trigger the flaw via crafted input, potentially reading, modifying, or corrupting metadata stored in the Hive Metastore database. Because the component is retired, there is no patched release, so every deployment of Griffin's Hive Metastore Module remains permanently vulnerable. Only organizations still running Apache Griffin — an unsupported data-quality service — are affected. No public proof-of-concept, KEV listing, or known in-the-wild exploitation has been reported, and the 0.3% EPSS score indicates low expected exploitation in the next 30 days.

What to do: No patched version exists, so restrict network access to the Griffin Hive Metastore instance to trusted users only (per the Apache advisory) and review whether it is exposed beyond trusted internal segments. Consider fronting the service with input-validation or WAF rules that block SQL injection patterns, and plan a migration to an alternative, maintained data-quality/metadata solution. Audit any remaining Griffin deployments for unusual metastore database queries.

Affected
Apache Griffin Hive Metastore Moduleall versions (project retired; no fix will be released)
Estimated exposure
nichelikely only a few hundred to low thousands of deployments worldwide — Apache Griffin was a niche data-quality service tied to Hadoop/Spark big-data stacks and was retired by the project, leaving only a small, shrinking install base with no published install counts or scan data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. This issue affects Apache Griffin Hive Metastore Module: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.