Vulnerabilities > Apache > Hive > High

DATE CVE VULNERABILITY TITLE RISK
2022-07-16 CVE-2021-34538 Missing Authentication for Critical Function vulnerability in Apache Hive
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query.
network
low complexity
apache CWE-306
7.5
2021-02-12 CVE-2020-13949 Resource Exhaustion vulnerability in multiple products
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
network
low complexity
apache oracle CWE-400
7.5
2018-11-08 CVE-2018-11777 Unspecified vulnerability in Apache Hive
In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
network
low complexity
apache
8.1
2017-05-30 CVE-2016-3083 Improper Certificate Validation vulnerability in Apache Hive
Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes).
network
low complexity
apache CWE-295
7.5
2016-01-29 CVE-2015-7521 Improper Authentication vulnerability in Apache Hive
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.
network
low complexity
apache CWE-287
8.3
2015-12-21 CVE-2015-1772 Improper Authentication vulnerability in multiple products
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
network
low complexity
ibm apache CWE-287
7.3