In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
References
| Link | Resource |
|---|---|
| http://www.securityfocus.com/bid/105886 | Third Party Advisory VDB Entry |
| https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb%40%3Cdev.hive.apache.org%3E |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-11-08 14:29
Updated : 2023-11-07 02:51
NVD link : CVE-2018-11777
Mitre link : CVE-2018-11777
CVE.ORG link : CVE-2018-11777
JSON object : View
Products Affected
apache
- hive
CWE
