CVE-2017-12625: Infoleak
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcement does not happen correctly on the table for masked columns.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12625?
CVE-2017-12625 is classified as a high-severity vulnerability due to improper policy enforcement on tables in Apache Hive.
How do I fix CVE-2017-12625?
To fix CVE-2017-12625, upgrade Apache Hive to version 2.1.2 or later, 2.2.1 or later, or 2.3.1 or later.
What versions of Apache Hive are affected by CVE-2017-12625?
Apache Hive versions 2.1.0, 2.1.1, 2.2.0, and 2.3.0 are affected by CVE-2017-12625.
What type of vulnerability is CVE-2017-12625?
CVE-2017-12625 is a vulnerability related to improper enforcement of masking policies when creating views on tables.
Who is affected by CVE-2017-12625?
Organizations using vulnerable versions of Apache Hive can be affected, particularly those using masking policies for sensitive data.