Back to Vulnerability Directory
HIGHFixed upstream

CVE-2021-34538

Apache Hive: CREATE and DROP FUNCTION skip authorization

Technology

Apache Hive

CVSS Score

7.5 / 10.0

Affected Versions

Apache Hive before 3.1.3

Upstream Fix

3.1.3, 4.0.0; no fix for 2.3 or 1.2

Published

July 16, 2022

OSSeva Coverage

Fixed upstream

Description

Hive's CREATE and DROP function operations do not check authorization on the entities involved, so an unauthorized user can drop an existing UDF and recreate it pointing at a new, possibly malicious jar. The fix, HIVE-25468, went into 3.1.3 and 4.0.0 only.

Upstream record: NVD · CVE.org

Is your Apache Hive deployment affected?

If you're running Apache Hive before 3.1.3, you need this patch. Book a discovery call to get covered.