Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-23953

Apache Hive: timing attack against LLAP message signatures

Technology

Apache Hive

CVSS Score

6.5 / 10.0

Affected Versions

Apache Hive 2.2.0 before 4.0.0

Upstream Fix

4.0.0

Published

January 28, 2025

OSSeva Coverage

Fixed upstream

Description

LlapSignerImpl compares message signatures with Arrays.equals(), which is not constant time, so an authorized user can forge a valid signature for an arbitrary message byte by byte and submit work to LLAP without running as a privileged user.

Upstream record: NVD · CVE.org

Is your Apache Hive deployment affected?

If you're running Apache Hive 2.2.0 before 4.0.0, you need this patch. Book a discovery call to get covered.