Skip to content
Apache HiveGHSA-5gvm-hrw5-h6xf

Improper Authentication in org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service

High7.3CVE-2015-1772 · Published Mar 14, 2019 · updated Nov 8, 2023

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.hive:hive-exec
Maven
>= 1.0.0, < 1.0.11.0.1
>= 1.1.0, < 1.1.11.1.1
Details and references

The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287
Also known as
CVE-2015-1772

More Apache Hive advisories

All Apache Hive
DateAdvisory
Mar 142019Moderate severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
CVE-2017-12625Medium4.3fixed in 2.1.2, 2.2.1, 2.3.1
Mar 142019org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service vulnerable to Improper Certificate Validation
CVE-2016-3083High7.5fixed in 1.2.2, 2.0.1
Nov 212018Improper Authentication in hive:hive-exec
CVE-2018-11777High8.1fixed in 2.3.4, 3.1.1
Nov 212018Exposure of Sensitive Information to an Unauthorized Actor in Apache hive
CVE-2018-1284Low3.7fixed in 2.3.3
Nov 212018Incorrect Permission Assignment for Critical Resource in Apache hive
CVE-2018-1315Low3.7fixed in 2.3.3
Nov 212018High severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
CVE-2015-7521High8.3fixed in 1.2.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.