Information Disclosure in Apache Hive by Apache
CVE-2017-12625
4.3MEDIUM
Summary
Apache Hive prior to versions 2.1.2, 2.2.1, and 2.3.1 allows the incorrect enforcement of masking policies for columns in tables or views. This flaw arises when a view is created over a table; the relevant policies are not applied correctly, potentially exposing sensitive information to unauthorized access. Users relying on column masking for data protection may find that their sensitive data remains visible. It is crucial for organizations using affected versions of Apache Hive to apply the latest updates to safeguard against potential data leaks.
Affected Version(s)
Apache Hive 2.1.x before 2.1.2
Apache Hive 2.2.x before 2.2.1
Apache Hive 2.3.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved