https://seclists.org/oss-sec/2025/q1/89: CVE-2024-29869: Apache Hive: Cdentials file cated with non strictive permissions
Published Jan 28, 2025
·Updated
Affected Software
1 affected component
Apache Hive<4.0.1
Frequently Asked Questions
1
What is the severity of CVE-2024-29869?
The severity of CVE-2024-29869 is classified as important.
2
Which versions of Apache Hive are affected by CVE-2024-29869?
CVE-2024-29869 affects Apache Hive versions 1.1.0 before 4.0.1.
3
What vulnerability does CVE-2024-29869 describe?
CVE-2024-29869 describes a vulnerability where a credentials file is created with non-restrictive permissions, allowing unauthorized access.
4
How do I mitigate the risk associated with CVE-2024-29869?
To mitigate CVE-2024-29869, users should explicitly set restrictive permissions for the credentials file generated by Apache Hive.
5
Is there a fix available for CVE-2024-29869?
Yes, upgrading to Apache Hive version 4.0.1 or later addresses the issue described in CVE-2024-29869.