CVE-2015-7521: High severity apache hive vulnerability
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7521?
CVE-2015-7521 has a medium severity rating due to its potential to bypass access restrictions.
How can I exploit CVE-2015-7521?
CVE-2015-7521 can be exploited by an attacker performing unauthorized partition-level operations to gain unintended access.
What versions of Apache Hive are affected by CVE-2015-7521?
CVE-2015-7521 affects Apache Hive versions 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0, and 1.2.1.
How do I fix CVE-2015-7521?
To mitigate CVE-2015-7521, upgrade Apache Hive to a version that includes patches for this vulnerability.
What systems are at risk from CVE-2015-7521?
Systems running vulnerable versions of Apache Hive with an authorization framework exposed are at risk from CVE-2015-7521.