Описание
Moderate severity vulnerability that affects org.apache.hive:hive-jdbc
In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.
Пакеты
Наименование
org.apache.hive:hive-jdbc
maven
Затронутые версииВерсия исправления
< 2.3.4
2.3.4
Наименование
org.apache.hive:hive-jdbc
maven
Затронутые версииВерсия исправления
>= 3.0.0, < 3.1.1
3.1.1
Связанные уязвимости
CVSS3: 4.3
nvd
больше 7 лет назад
In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.