CVE-2018-1284: Infoleak
In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpathstring/xpathboolean/xpathnumber/xpathdouble/xpathfloat/xpathlong/xpathint/xpathshort) to expose the content of a file on the machine running HiveServer2 owned by HiveServer2 user (usually hive) if hive.server2.enable.doAs=false.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Apache Hive vulnerability?
The vulnerability ID for this Apache Hive vulnerability is CVE-2018-1284.
What is the severity of CVE-2018-1284?
The severity of CVE-2018-1284 is medium.
Which versions of Apache Hive are affected by this vulnerability?
Apache Hive versions 0.6.0 to 2.3.2 are affected by this vulnerability.
How can a malicious user exploit this vulnerability?
A malicious user can exploit this vulnerability by using any xpath UDFs to expose the content of a file on the machine running HiveServer2.
Are there any references available for this vulnerability?
Yes, you can find references for this vulnerability at the following links: [1](http://www.securityfocus.com/bid/103750), [2](https://lists.apache.org/thread.html/29184dbce4a37be2af36e539ecb479b1d27868f73ccfdff46c7174b4@%3Cdev.hive.apache.org%3E)