In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
2018-11-08T14:29:00.197
2024-11-21T03:44:00.963
Modified
CVSSv3.0: 8.1 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | hive | ≤ 2.3.3 | Yes |
Application | apache | hive | ≤ 3.1.0 | Yes |