Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths (CVE-2026-49845) | HOL Guard CVE