Back to Vulnerability Directory
HIGHFixed upstream

CVE-2018-11777

Apache Hive: local resources on HiveServer2 hosts unprotected without an authorizer

Technology

Apache Hive

CVSS Score

8.1 / 10.0

Affected Versions

All Apache Hive versions through 2.3.3 and 3.1.0

Upstream Fix

2.3.4, 3.1.1, with FallbackHiveAuthorizerFactory configured

Published

November 8, 2018

OSSeva Coverage

Fixed upstream

Description

When Ranger, Sentry or SQL standard authorization is not in use, a malicious user can reach local resources on HiveServer2 machines. The fix adds a fallback authorizer that blocks local file locations and dfs commands for non-admin users, blocks ADD JAR, COMPILE and TRANSFORM, and limits SET to an allowlist; it has to be enabled in hiveserver2-site.xml.

Upstream record: NVD · CVE.org

Is your Apache Hive deployment affected?

If you're running All Apache Hive versions through 2.3.3 and 3.1.0, you need this patch. Book a discovery call to get covered.