QID 980828
QID 980828: Java (maven) Security Update for org.apache.hive:hive-exec (GHSA-w4x9-4f5x-8jj8)
Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w4x9-4f5x-8jj8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-w4x9-4f5x-8jj8 -
github.com/advisories/GHSA-w4x9-4f5x-8jj8
CVEs related to QID 980828
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w4x9-4f5x-8jj8 | org.apache.hive:hive |
|
|
| GHSA-w4x9-4f5x-8jj8 | org.apache.hive:hive-exec |
|
|
| GHSA-w4x9-4f5x-8jj8 | org.apache.hive:hive-service |
|