Missing Authentication for Critical Function in Apache Hive - CVE-2021-34538

 

Missing Authentication for Critical Function in Apache Hive - CVE-2021-34538

Published: May 24, 2023


Vulnerability identifier: #VU76481
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34538
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to CREATE() and DROP() function operations does not check for necessary authorization of involved entities in the query. A remote unauthenticated attacker can manipulate an existing UDF to drop and recreate UDFs pointing them to new jars that could be potentially malicious.


Affected software

Apache Hive
IBM InfoSphere Information Server
IBM Operations Analytics Predictive Insights
QRadar User Behavior Analytics
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2021-34538

Install updates from vendor's website.

Apache Hive - update to 3.1.3
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
QRadar User Behavior Analytics - update to 4.1.9
IBM Cloud Pak for Watson AIOps - update to 4.6.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins