Apache HiveGHSA-rrfq-g5fq-fc9c
Improper Authentication in hive:hive-exec
High8.1CVE-2018-11777 · Published Nov 21, 2018 · updated Dec 2, 2024
In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.hive:hive-exec Maven | >= 3.0.0, < 3.1.1 | 3.1.1 |
| < 2.3.4 | 2.3.4 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Also known as
- CVE-2018-11777
More Apache Hive advisories
All Apache Hive| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 142019 | Apache Hive: improper certificate validation | High7.5 | 1.2.2+1 more |
| Mar 142019 | Apache Hive: information disclosure | Medium4.3 | 2.1.2+2 more |
| Nov 212018 | Exposure of Sensitive Information to an Unauthorized Actor in Apache hive | Low3.7 | 2.3.3 |
| Nov 212018 | Incorrect Permission Assignment for Critical Resource in Apache hive | Low3.7 | 2.3.3 |
| Nov 212018 | Apache Hive: improper authentication | High8.3 | 1.2.2 |
| Nov 212018 | Apache Hive: information disclosure | Low | 0.13.1 |