CVE-2018-11777

8.1HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
8 November 2018

Summary

In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.

Affected Version(s)

Apache Hive All versions of Hive, including 2.3.3, 3.1.0 and earlier

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.