First published: Thu Nov 08 2018(Updated: )
In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Hive | <=2.3.3 | |
Apache Hive | >=3.0.0<=3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11777 is high with a score of 8.1.
CVE-2018-11777 is a vulnerability in Apache Hive versions 2.3.3, 3.0.0, and 3.1.0 that allows malicious users to access local resources on HiveServer2 machines if certain authorizers are not in use.
CVE-2018-11777 affects Apache Hive versions 2.3.3, 3.0.0, and 3.1.0.
To protect your system from CVE-2018-11777, ensure that ranger, sentry, or sql standard authorizer is in use on your HiveServer2 machines.
You can find more information about CVE-2018-11777 on the following websites: [http://www.securityfocus.com/bid/105886](http://www.securityfocus.com/bid/105886) and [https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb@%3Cdev.hive.apache.org%3E](https://lists.apache.org/thread.html/963c8e2516405c9b532b4add16c03b2c5db621e0c83e80f45049cbbb@%3Cdev.hive.apache.org%3E)