Skip to content

Conversation

@rtrivedi12
Copy link
Contributor

What changes were proposed in this pull request?

  1. Restricting temporary or permanent function creation with Blacklisted UDFs
  2. Changing Default blacklisted UDFs to include reflect, in_file, java_method functions

Why are the changes needed?

These functions using blacklisted udfs can be exploited; a security hole

Does this PR introduce any user-facing change?

Yes, the User will see Semantic Exception and function creation will fail using blacklisted UDF class

How was this patch tested?

Manually

@sonarqubecloud
Copy link

@github-actions
Copy link

This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs.
Feel free to reach out on the dev@hive.apache.org list if the patch is in need of reviews.

@github-actions github-actions bot added the stale label Nov 24, 2025
@github-actions github-actions bot closed this Dec 1, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants