Description
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6416 | Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious. |
Github GHSA |
GHSA-v3p8-j597-3xg8 | Apache Hive before 3.1.3 `CREATE` and `DROP` function operations do not check for necessary authorization. |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T00:12:50.447Z
Reserved: 2021-06-10T00:00:00.000Z
Link: CVE-2021-34538
No data.
Status : Modified
Published: 2022-07-16T07:15:08.530
Modified: 2024-11-21T06:10:37.843
Link: CVE-2021-34538
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA