Apache HiveGHSA-2g9q-chq2-w8qw
Moderate severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
Medium4.3CVE-2017-12625 · Published Mar 14, 2019 · updated Nov 8, 2023
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.hive:hive-exec Maven | >= 2.1.0, < 2.1.2 | 2.1.2 |
| >= 2.2.0, < 2.2.1 | 2.2.1 | |
| >= 2.3.0, < 2.3.1 | 2.3.1 |
Details and references
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcement does not happen correctly on the table for masked columns.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- CVE-2017-12625
More Apache Hive advisories
All Apache Hive| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 142019 | org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service vulnerable to Improper Certificate Validation CVE-2016-3083High7.5fixed in 1.2.2, 2.0.1 | High7.5 | 1.2.2, 2.0.1 |
| Mar 142019 | Improper Authentication in org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service CVE-2015-1772High7.3fixed in 1.0.1, 1.1.1 | High7.3 | 1.0.1, 1.1.1 |
| Nov 212018 | Improper Authentication in hive:hive-exec CVE-2018-11777High8.1fixed in 2.3.4, 3.1.1 | High8.1 | 2.3.4, 3.1.1 |
| Nov 212018 | Exposure of Sensitive Information to an Unauthorized Actor in Apache hive CVE-2018-1284Low3.7fixed in 2.3.3 | Low3.7 | 2.3.3 |
| Nov 212018 | Incorrect Permission Assignment for Critical Resource in Apache hive CVE-2018-1315Low3.7fixed in 2.3.3 | Low3.7 | 2.3.3 |
| Nov 212018 | High severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service CVE-2015-7521High8.3fixed in 1.2.2 | High8.3 | 1.2.2 |