CVE-2018-11777

Description

In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.413

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-11777 are fixed in Apache-hive-exec 3.1.1Windows
Vulnerabilities CVE-2018-11777 are fixed in Apache-hive-exec 2.3.4Windows
Vulnerabilities CVE-2018-11777 are fixed in Apache-hive-exec for Linux 3.1.1Linux
Vulnerabilities CVE-2018-11777 are fixed in Apache-hive-exec for Linux 2.3.4Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234