Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v3p8-j597-3xg8

Опубликовано: 17 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache Hive before 3.1.3 CREATE and DROP function operations do not check for necessary authorization.

Apache Hive before 3.1.3 CREATE and DROP function operations do not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.

Пакеты

Наименование

org.apache.hive:hive

maven
Затронутые версииВерсия исправления

< 3.1.3

3.1.3

EPSS

Процентиль: 63%
0.00451
Низкий

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.

EPSS

Процентиль: 63%
0.00451
Низкий

7.5 High

CVSS3

Дефекты

CWE-306