QID 981008
QID 981008: Java (maven) Security Update for org.apache.hive:hive-jdbc (GHSA-jmf4-pq78-f8vj)
In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jmf4-pq78-f8vj for updates pertaining to this vulnerability.
Vendor References
- GHSA-jmf4-pq78-f8vj -
github.com/advisories/GHSA-jmf4-pq78-f8vj
CVEs related to QID 981008
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jmf4-pq78-f8vj | org.apache.hive:hive-jdbc |
|