Описание
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
Ссылки
- Issue TrackingPatchVendor Advisory
- Mailing ListPatchVendor Advisory
- Issue TrackingPatchVendor Advisory
- Mailing ListPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.8 (исключая)
cpe:2.3:a:apache:hive:*:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00478
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-208
CWE-203
Связанные уязвимости
CVSS3: 5.9
github
почти 4 года назад
Apache Hive Information Exposure and Observable Timing Discrepancy
EPSS
Процентиль: 64%
0.00478
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-208
CWE-203