CVE-2020-1926
- EPSS 2.46%
- Veröffentlicht 16.03.2021 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:37
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
CVE-2020-13949
- EPSS 6.78%
- Veröffentlicht 12.02.2021 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:02:12
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
CVE-2018-21234
- EPSS 8.32%
- Veröffentlicht 21.05.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:03:14
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
CVE-2018-1314
- EPSS 1.99%
- Veröffentlicht 08.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:36
In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.
CVE-2018-11777
- EPSS 2.3%
- Veröffentlicht 08.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:00
In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
CVE-2018-1315
- EPSS 1.78%
- Veröffentlicht 05.04.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:59:36
In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statement is run using HPL/SQL extension to Hive, a compromised/malicious FTP server can cause the file to be written to an arbitrary location on the cluster where the command is run from. This is b...
CVE-2018-1284
- EPSS 2.19%
- Veröffentlicht 05.04.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:59:32
In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned ...
CVE-2018-1282
- EPSS 5.59%
- Veröffentlicht 05.04.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:32
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
CVE-2017-12625
- EPSS 1.43%
- Veröffentlicht 01.11.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcem...
CVE-2016-3083
- EPSS 1.01%
- Veröffentlicht 30.05.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificate during the connection setup, the client in Apache Hive before 1.2.2 and 2.0.x before 2.0....