CVE-2018-11777
Apache Hive: local resources on HiveServer2 hosts unprotected without an authorizer
Technology
Apache Hive
CVSS Score
8.1 / 10.0
Affected Versions
All Apache Hive versions through 2.3.3 and 3.1.0
Upstream Fix
2.3.4, 3.1.1, with FallbackHiveAuthorizerFactory configured
Published
November 8, 2018
OSSeva Coverage
Fixed upstream
Description
When Ranger, Sentry or SQL standard authorization is not in use, a malicious user can reach local resources on HiveServer2 machines. The fix adds a fallback authorizer that blocks local file locations and dfs commands for non-admin users, blocks ADD JAR, COMPILE and TRANSFORM, and limits SET to an allowlist; it has to be enabled in hiveserver2-site.xml.
Is your Apache Hive deployment affected?
If you're running All Apache Hive versions through 2.3.3 and 3.1.0, you need this patch. Book a discovery call to get covered.