Security restrictions bypass in Apache Hive - CVE-2018-11777

 

Security restrictions bypass in Apache Hive - CVE-2018-11777

Published: November 9, 2018


Vulnerability identifier: #VU15782
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11777
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to bypass security restrictions on the target system.

The vulnerability exists due to improper security restrictions on local resources on HiveServer2 servers. A remote authenticated attacker can bypass security restrictions, access or modify any file if the Ranger, Sentry or SQL Standard authorizers are not in use and conduct further attacks.


Affected software

Apache Hive

How to mitigate CVE-2018-11777

The vulnerability has been fixed in the versions 2.3.4, 3.1.1.

Apache Hive - addressed in versions 2.3.4, 3.1.1

External References

Related Security Bulletins