Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54g4-5cf6-hjp3

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Apache Hive Information Exposure and Observable Timing Discrepancy

Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8

Пакеты

Наименование

org.apache.hive:hive

maven
Затронутые версииВерсия исправления

< 2.3.8

2.3.8

EPSS

Процентиль: 64%
0.00478
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-200
CWE-203
CWE-208

Связанные уязвимости

CVSS3: 5.9
nvd
почти 5 лет назад

Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8

EPSS

Процентиль: 64%
0.00478
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-200
CWE-203
CWE-208