← Back

CVE-2018-1314

nvd nist
Published: Nov 8, 2018Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.

Affected (2)

Products: Apache: Hive
1 product
Hive
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Up to 2.3.3
From 3.0.0 to 3.1.0

References (4)

Timeline

No history available yet.