logo

CVE-2018-1284 org.apache.hive:hive

Package

Manager: maven
Name: org.apache.hive:hive
Vulnerable Version: >=0.6.0 <2.3.3

Severity

Level: Low

CVSS v3.1: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00469 pctl0.63596

Details

Exposure of Sensitive Information to an Unauthorized Actor in Apache hive In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveServer2 user (usually hive) if hive.server2.enable.doAs=false.

Metadata

Created: 2018-11-21T22:24:22Z
Modified: 2024-03-04T20:12:18Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/11/GHSA-rxmr-c9jm-7mm8/GHSA-rxmr-c9jm-7mm8.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-rxmr-c9jm-7mm8
Finding: F310
Auto approve: 1