Information Disclosure in Apache Hive by Apache
CVE-2017-12625
4.3MEDIUM
What is CVE-2017-12625?
Apache Hive prior to versions 2.1.2, 2.2.1, and 2.3.1 allows the incorrect enforcement of masking policies for columns in tables or views. This flaw arises when a view is created over a table; the relevant policies are not applied correctly, potentially exposing sensitive information to unauthorized access. Users relying on column masking for data protection may find that their sensitive data remains visible. It is crucial for organizations using affected versions of Apache Hive to apply the latest updates to safeguard against potential data leaks.
Affected Version(s)
Apache Hive 2.1.x before 2.1.2
Apache Hive 2.2.x before 2.2.1
Apache Hive 2.3.0