Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2024-23953
Apache Hive: timing attack against LLAP message signatures
Technology
Apache Hive
CVSS Score
6.5 / 10.0
Affected Versions
Apache Hive 2.2.0 before 4.0.0
Upstream Fix
4.0.0
Published
January 28, 2025
OSSeva Coverage
Fixed upstream
Is your Apache Hive deployment affected?
If you're running Apache Hive 2.2.0 before 4.0.0, you need this patch. Book a discovery call to get covered.