CVE-2017-12625

4.3MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
1 November 2017

Summary

Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcement does not happen correctly on the table for masked columns.

Affected Version(s)

Apache Hive 2.1.x before 2.1.2

Apache Hive 2.2.x before 2.2.1

Apache Hive 2.3.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.