CVE-2018-11777: High severity apache hive vulnerability
In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11777?
The severity of CVE-2018-11777 is high with a score of 8.1.
What is the description of CVE-2018-11777?
CVE-2018-11777 is a vulnerability in Apache Hive versions 2.3.3, 3.0.0, and 3.1.0 that allows malicious users to access local resources on HiveServer2 machines if certain authorizers are not in use.
Which software versions are affected by CVE-2018-11777?
CVE-2018-11777 affects Apache Hive versions 2.3.3, 3.0.0, and 3.1.0.
How can I protect my system from CVE-2018-11777?
To protect your system from CVE-2018-11777, ensure that ranger, sentry, or sql standard authorizer is in use on your HiveServer2 machines.
Where can I find more information about CVE-2018-11777?
You can find more information about CVE-2018-11777 on the following websites: [http://www.securityfocus.com/bid/105886](http://www.securityfocus.com/bid/105886) and [https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb@%3Cdev.hive.apache.org%3E](https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb@%3Cdev.hive.apache.org%3E)