Apache HiveGHSA-83r3-c79w-f6wc
Apache Hive: improper authentication
High8.3CVE-2015-7521 · Published Nov 21, 2018 · updated Nov 8, 2023
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.hive:hive-exec Maven | >= 1.0.0, < 1.2.2 | 1.2.2 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-287
- Also known as
- CVE-2015-7521
- nvd.nist.gov/vuln/detail/CVE-2015-7521
- github.com/advisories/GHSA-83r3-c79w-f6wc
- mail-archives.apache.org/mod_mbox/hive-user/201601.mbox/%3C20160128205008.2154F185EB%40minotaur.apache.org%3E
- packetstormsecurity.com/files/135836/Apache-Hive-Authorization-Bypass.html
- www.openwall.com/lists/oss-security/2016/01/28/12
- www.securityfocus.com/archive/1/537549/100/0/threaded
More Apache Hive advisories
All Apache Hive| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 142019 | Apache Hive: improper certificate validation | High7.5 | 1.2.2+1 more |
| Mar 142019 | Apache Hive: information disclosure | Medium4.3 | 2.1.2+2 more |
| Nov 212018 | Improper Authentication in hive:hive-exec | High8.1 | 2.3.4+1 more |
| Nov 212018 | Exposure of Sensitive Information to an Unauthorized Actor in Apache hive | Low3.7 | 2.3.3 |
| Nov 212018 | Incorrect Permission Assignment for Critical Resource in Apache hive | Low3.7 | 2.3.3 |
| Nov 212018 | Apache Hive: information disclosure | Low | 0.13.1 |