Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23945


Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value, which can lead to security vulnerabilities and exploitation. Apache Hive’s service component accidentally exposes the signed cookie to the end user when there is a mismatch in signature between the current and expected cookie. Exposing the correct cookie signature can lead to further exploitation. The vulnerable CookieSigner logic was introduced in Apache Hive by HIVE-9710 (1.2.0) and in Apache Spark by SPARK-14987 (2.0.0). The affected components are the following: * org.apache.hive:hive-service * org.apache.spark:spark-hive-thriftserver_2.11 * org.apache.spark:spark-hive-thriftserver_2.12


Published

2024-12-23T16:15:05.590

Last Modified

2025-07-14T18:32:34.607

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-209
  • Type: Secondary
    CWE-209

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache hive < 4.0.0 Yes
Application apache spark < 3.3.4 Yes
Application apache spark < 3.4.2 Yes
Application apache spark 3.5.0 Yes

References