SSL Certificate Verification Issue in Apache Hive by The Apache Software Foundation
CVE-2016-3083
7.5HIGH
What is CVE-2016-3083?
A problematic SSL certificate validation in Apache Hive versions prior to 1.2.2 and 2.0.x prior to 2.0.1 permits a JDBC client to accept an SSL certificate without correctly verifying the common name attribute. This implies that an attacker could potentially exploit this oversight by providing a valid SSL certificate issued for a different domain, allowing for a successful SSL handshake and unauthorized access to sensitive information.
Affected Version(s)
Apache Hive 0.11.0 - 0.14.0
Apache Hive 1.0.0 - 1.2.1
Apache Hive 2.0.0