Apache HiveGHSA-5gvm-hrw5-h6xf
Improper Authentication in org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
High7.3CVE-2015-1772 · Published Mar 14, 2019 · updated Nov 8, 2023
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.hive:hive-exec Maven | >= 1.0.0, < 1.0.1 | 1.0.1 |
| >= 1.1.0, < 1.1.1 | 1.1.1 |
Details and references
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-287
- Also known as
- CVE-2015-1772
- nvd.nist.gov/vuln/detail/CVE-2015-1772
- github.com/advisories/GHSA-5gvm-hrw5-h6xf
- www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
- mail-archives.apache.org/mod_mbox/www-announce/201505.mbox/%3CCAOpgucy52yzNN1FaRcxwhZmx8ZtNRjmK6V0Bxk4svAD-R1q70Q@mail.gmail.com%3E
- www-01.ibm.com/support/docview.wss?uid=swg21969546
- www.securitytracker.com/id/1034365
More Apache Hive advisories
All Apache Hive| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 142019 | Moderate severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service CVE-2017-12625Medium4.3fixed in 2.1.2, 2.2.1, 2.3.1 | Medium4.3 | 2.1.2, 2.2.1, 2.3.1 |
| Mar 142019 | org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service vulnerable to Improper Certificate Validation CVE-2016-3083High7.5fixed in 1.2.2, 2.0.1 | High7.5 | 1.2.2, 2.0.1 |
| Nov 212018 | Improper Authentication in hive:hive-exec CVE-2018-11777High8.1fixed in 2.3.4, 3.1.1 | High8.1 | 2.3.4, 3.1.1 |
| Nov 212018 | Exposure of Sensitive Information to an Unauthorized Actor in Apache hive CVE-2018-1284Low3.7fixed in 2.3.3 | Low3.7 | 2.3.3 |
| Nov 212018 | Incorrect Permission Assignment for Critical Resource in Apache hive CVE-2018-1315Low3.7fixed in 2.3.3 | Low3.7 | 2.3.3 |
| Nov 212018 | High severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service CVE-2015-7521High8.3fixed in 1.2.2 | High8.3 | 1.2.2 |