Permissions problem in the Apache Ranger Hive Plugin
CVE-2021-40331

8.1HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
5 May 2023

Summary

An Incorrect Permission Assignment for Critical Resource vulnerability exists in the Apache Ranger Hive Plugin, allowing any user with SELECT privilege on a database to modify the ownership of a table in Hive. This vulnerability impacts versions 2.0.0 to 2.3.0 and poses significant risks to data integrity. Users are strongly advised to upgrade to version 2.4.0 or higher to mitigate these security risks.

Affected Version(s)

Apache Ranger Hive Plugin 2.0.0 <= 2.3.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.