Incorrect permission assignment for critical resource in Apache Hive - CVE-2024-29869

 

Incorrect permission assignment for critical resource in Apache Hive - CVE-2024-29869

Published: June 26, 2025


Vulnerability identifier: #VU111975
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-29869
CWE-ID: CWE-732
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. A local user with access to the directory can read the sensitive information written into this file.


Affected software

Apache Hive
Netcool Operations Insight
watsonx.data
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2024-29869

Install updates from vendor's website.

Apache Hive - update to 4.0.1
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0

External References

Related Security Bulletins