Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-29869

Apache Hive: credentials file created with world-readable permissions

Technology

Apache Hive

CVSS Score

5.5 / 10.0

Affected Versions

Apache Hive 1.1.0 before 4.0.1

Upstream Fix

4.0.1

Published

January 28, 2025

OSSeva Coverage

Fixed upstream

Description

When file permissions are not set explicitly, Hive writes a credentials file to a temporary directory with permissions 644, so any local user with access to that directory can read the sensitive information in it. The fix, HIVE-28134, shipped only in 4.0.1 and 4.1.0.

Upstream record: NVD · CVE.org

Is your Apache Hive deployment affected?

If you're running Apache Hive 1.1.0 before 4.0.1, you need this patch. Book a discovery call to get covered.