#VU15781 Security restrictions bypass in Apache Hive - CVE-2018-1314
Published: November 8, 2018 / Updated: November 9, 2018
Apache Hive
Apache Foundation
Description
The vulnerability allows a remote authenticated attacker to bypass security restrictions on the target system.
The vulnerability exists due to improper security restrictions when the EXPLAIN operation is used. A remote authenticated attacker can use the EXPLAIN operation in a query, bypass security restrictions, access or modify any file and conduct further attacks.