Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-23945

Apache Hive: CookieSigner exposes the correct signature on verification failure

Technology

Apache Hive

CVSS Score

5.9 / 10.0

Affected Versions

Apache Hive 1.2.0 before 4.0.0 (hive-service)

Upstream Fix

4.0.0

Published

December 23, 2024

OSSeva Coverage

Fixed upstream

Description

The HiveServer2 CookieSigner, added in 1.2.0 for cookie-based authentication over HTTP, returns the correct signature to the client when a cookie's signature does not match, which can lead to further exploitation. The same code in the Spark Hive Thrift server is covered by this CVE too.

Upstream record: NVD · CVE.org

Is your Apache Hive deployment affected?

If you're running Apache Hive 1.2.0 before 4.0.0 (hive-service), you need this patch. Book a discovery call to get covered.