Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2024-29869
Apache Hive: credentials file created with world-readable permissions
Technology
Apache Hive
CVSS Score
5.5 / 10.0
Affected Versions
Apache Hive 1.1.0 before 4.0.1
Upstream Fix
4.0.1
Published
January 28, 2025
OSSeva Coverage
Fixed upstream
Description
When file permissions are not set explicitly, Hive writes a credentials file to a temporary directory with permissions 644, so any local user with access to that directory can read the sensitive information in it. The fix, HIVE-28134, shipped only in 4.0.1 and 4.1.0.
Is your Apache Hive deployment affected?
If you're running Apache Hive 1.1.0 before 4.0.1, you need this patch. Book a discovery call to get covered.