Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjr2-wpfh-5r9p

Опубликовано: 05 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Apache Ranger Hive Plugin missing permissions check

An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.

Пакеты

Наименование

org.apache.ranger:ranger-hive-plugin

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.4.0

2.4.0

EPSS

Процентиль: 33%
0.00133
Низкий

8.1 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 8.1
nvd
почти 3 года назад

An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.

EPSS

Процентиль: 33%
0.00133
Низкий

8.1 High

CVSS3

Дефекты

CWE-732