← Back

CVE-2018-11777

nvd nist
Published: Nov 8, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.

Affected (2)

Products: Apache: Hive
1 product
Hive
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Up to 2.3.3
From 3.0.0 to 3.1.0

References (4)

Timeline

No history available yet.