QID 980872
QID 980872: Java (maven) Security Update for org.apache.hive:hive-exec (GHSA-rrfq-g5fq-fc9c)
In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rrfq-g5fq-fc9c for updates pertaining to this vulnerability.
Vendor References
- GHSA-rrfq-g5fq-fc9c -
github.com/advisories/GHSA-rrfq-g5fq-fc9c
CVEs related to QID 980872
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rrfq-g5fq-fc9c | org.apache.hive:hive-exec |
|