QID 981291
QID 981291: Java (maven) Security Update for org.apache.hive:hive-service (GHSA-5gvm-hrw5-h6xf)
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5gvm-hrw5-h6xf for updates pertaining to this vulnerability.
Vendor References
- GHSA-5gvm-hrw5-h6xf -
github.com/advisories/GHSA-5gvm-hrw5-h6xf
CVEs related to QID 981291
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5gvm-hrw5-h6xf | org.apache.hive:hive |
|
|
| GHSA-5gvm-hrw5-h6xf | org.apache.hive:hive-exec |
|
|
| GHSA-5gvm-hrw5-h6xf | org.apache.hive:hive-service |
|