[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] [Security] CVE-2021-34538: Security vulnerability in Hive with UDFs
From:       Naveen Gangam <ngangam () cloudera ! com>
Date:       2022-07-15 21:40:36
Message-ID: CADx9buP8OWYN2zjjhHmatNvsVPwpii6ic7Dw437BP7COe8NUKQ () mail ! gmail ! com
[Download RAW message or body]


*CVE-2021-34538*: Unauthorized access to Hive UDFs

*Severity*: Very Important

*Vendor*: The Apache Software Foundation

*Versions Affected*: This vulnerability affects all versions of Hive prior
to Hive 3.1.3. (3.1.2 or earlier).

*Version Fixed:* Hive 3.1.3, Hive 4.0 (in Beta)

*Description*: Hive's "CREATE" and "DROP" function operations does not
check for necessary authorization of involved entities in the query. It was
found that an unauthorized user can manipulate an existing UDF without
having the privileges to do so. This allowed unauthorized or
underprivileged users to drop and recreate UDFs pointing them to new jars
that could be potentially malicious.

Mitigation: This vulnerability has been addressed vio HIVE-25468 in Hive
3.1.3 release and will be included in Hive 4.0GA (Already in the beta
releases). Please upgrade to one of the releases containing the fix or
apply this patch to an existing release.

Credit: This vulnerability was discovered and reported by Hideyuki Furue.
THANK YOU !!!


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic