First published: Wed Jun 14 2017(Updated: )
In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ranger | <=0.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7677 is considered a medium severity vulnerability due to improper permission checks.
To fix CVE-2017-7677, upgrade Apache Ranger to version 0.7.1 or later.
CVE-2017-7677 can allow unauthorized users to create tables, potentially leading to data breaches or information leaks.
Apache Ranger versions before 0.7.1 are affected by CVE-2017-7677.
The Hive Authorizer component in Apache Ranger is specifically vulnerable in CVE-2017-7677.