Authorization Bypass in Apache Hive by Apache
CVE-2015-7521
8.3HIGH
What is CVE-2015-7521?
An issue within the authorization framework of Apache Hive versions 1.0.0 to 1.2.1 allows unauthorized users to manipulate table access controls. Specifically, attackers can bypass intended restrictions meant to govern access rights to parent tables through certain, unspecified operations at the partition level. This vulnerability raises significant concerns regarding data security and access management in clusters secured by Ranger and SqlStdHiveAuthorization.