In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb@%3Cdev.hive.apache.org%3E | Mitigation Mailing List Vendor Advisory |
| http://www.securityfocus.com/bid/105886 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-11-08 06:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-11777
Mitre link : CVE-2018-11777
JSON object : View
CWE
Products Affected
apache
- hive


