CVE-2020-1926: Timing attack in Cookie signature verification
Published Mar 16, 2021
·Updated
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
Affected Software
1 affected component
Apache Hive<2.3.8
Remediation
Patch Available
Event History
Mar 16, 2021
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-1926.
2
What is the severity of CVE-2020-1926?
The severity of CVE-2020-1926 is medium with a severity value of 5.9.
3
What software is affected by CVE-2020-1926?
Apache Hive versions up to and including 2.3.8 are affected by CVE-2020-1926.
4
What is the description of CVE-2020-1926?
CVE-2020-1926 is a vulnerability in Apache Hive that allows recovery of another user's cookie signature due to a non constant time comparison vulnerability.
5
How has Apache Hive addressed CVE-2020-1926?
Apache Hive 2.3.8 has addressed CVE-2020-1926.