Vulnerabilities > Apache > Hive > 0.7.0

DATE CVE VULNERABILITY TITLE RISK
2022-07-16 CVE-2021-34538 Missing Authentication for Critical Function vulnerability in Apache Hive
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query.
network
low complexity
apache CWE-306
7.5
2021-03-16 CVE-2020-1926 Information Exposure Through Discrepancy vulnerability in Apache Hive
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks.
network
high complexity
apache CWE-203
5.9
2021-02-12 CVE-2020-13949 Resource Exhaustion vulnerability in multiple products
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
network
low complexity
apache oracle CWE-400
7.5
2018-11-08 CVE-2018-1314 Missing Authorization vulnerability in Apache Hive
In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query.
network
low complexity
apache CWE-862
4.3
2018-11-08 CVE-2018-11777 Unspecified vulnerability in Apache Hive
In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
network
low complexity
apache
8.1
2018-04-05 CVE-2018-1284 Information Exposure vulnerability in Apache Hive
In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveServer2 user (usually hive) if hive.server2.enable.doAs=false.
network
high complexity
apache CWE-200
3.7