QID 981216
QID 981216: Java (maven) Security Update for org.apache.hive:hive-service (GHSA-83r3-c79w-f6wc)
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-83r3-c79w-f6wc for updates pertaining to this vulnerability.
Vendor References
- GHSA-83r3-c79w-f6wc -
github.com/advisories/GHSA-83r3-c79w-f6wc
CVEs related to QID 981216
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-83r3-c79w-f6wc | org.apache.hive:hive |
|
|
| GHSA-83r3-c79w-f6wc | org.apache.hive:hive-exec |
|
|
| GHSA-83r3-c79w-f6wc | org.apache.hive:hive-service |
|