Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2024-23945
Apache Hive: CookieSigner exposes the correct signature on verification failure
Technology
Apache Hive
CVSS Score
5.9 / 10.0
Affected Versions
Apache Hive 1.2.0 before 4.0.0 (hive-service)
Upstream Fix
4.0.0
Published
December 23, 2024
OSSeva Coverage
Fixed upstream
Description
The HiveServer2 CookieSigner, added in 1.2.0 for cookie-based authentication over HTTP, returns the correct signature to the client when a cookie's signature does not match, which can lead to further exploitation. The same code in the Spark Hive Thrift server is covered by this CVE too.
Is your Apache Hive deployment affected?
If you're running Apache Hive 1.2.0 before 4.0.0 (hive-service), you need this patch. Book a discovery call to get covered.