CVE-2015-7521
HIGHApache Hive <1.3 - Auth Bypass
Title source: llmDescription
The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.
References (4)
Scores
CVSS v3
8.3
EPSS
0.0040
EPSS Percentile
60.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Classification
CWE
CWE-287
Status
draft
Affected Products (8)
apache/hive
apache/hive
apache/hive
apache/hive
apache/hive
org.apache.hive/hive
< 1.2.2Maven
org.apache.hive/hive-exec
< 1.2.2Maven
org.apache.hive/hive-service
< 1.2.2Maven
Timeline
Published
Jan 29, 2016
Tracked Since
Feb 18, 2026