In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:44
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/105886 - Third Party Advisory, VDB Entry | |
References | () https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb%40%3Cdev.hive.apache.org%3E - |
07 Nov 2023, 02:51
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2018-11-08 14:29
Updated : 2024-11-21 03:44
NVD link : CVE-2018-11777
Mitre link : CVE-2018-11777
CVE.ORG link : CVE-2018-11777
JSON object : View
Products Affected
apache
- hive
CWE