CVE-2018-11777

In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:hive:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:hive:*:*:*:*:*:*:*:*

History

07 Nov 2023, 02:51

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb@%3Cdev.hive.apache.org%3E', 'name': 'https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb@%3Cdev.hive.apache.org%3E', 'tags': ['Mailing List', 'Mitigation', 'Vendor Advisory'], 'refsource': 'MISC'}
  • () https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb%40%3Cdev.hive.apache.org%3E -

Information

Published : 2018-11-08 14:29

Updated : 2023-12-10 12:44


NVD link : CVE-2018-11777

Mitre link : CVE-2018-11777

CVE.ORG link : CVE-2018-11777


JSON object : View

Products Affected

apache

  • hive