CVE-2018-11777

In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:hive:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:hive:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:44

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/105886 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/105886 - Third Party Advisory, VDB Entry
References () https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb%40%3Cdev.hive.apache.org%3E - () https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb%40%3Cdev.hive.apache.org%3E -

07 Nov 2023, 02:51

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb@%3Cdev.hive.apache.org%3E', 'name': 'https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb@%3Cdev.hive.apache.org%3E', 'tags': ['Mitigation', 'Mailing List', 'Vendor Advisory'], 'refsource': 'MISC'}
  • () https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb%40%3Cdev.hive.apache.org%3E -

Information

Published : 2018-11-08 14:29

Updated : 2024-11-21 03:44


NVD link : CVE-2018-11777

Mitre link : CVE-2018-11777

CVE.ORG link : CVE-2018-11777


JSON object : View

Products Affected

apache

  • hive