CVE-2015-7521

HIGH

Apache Hive 1.0.0-1.2.1 - Authorization Bypass via Partition-Level Operations

Title source: llm
STIX 2.1

Description

The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/01/28/12
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/537549/100/0/threaded

Scores

CVSS v3 8.3
EPSS 0.0040
EPSS Percentile 61.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Details

CWE
CWE-287
Status published
Products (8)
apache/hive 1.0.0
apache/hive 1.0.1
apache/hive 1.1.0
apache/hive 1.2.0
apache/hive 1.2.1
org.apache.hive/hive 1.0.0 - 1.2.2Maven
org.apache.hive/hive-exec 1.0.0 - 1.2.2Maven
org.apache.hive/hive-service 1.0.0 - 1.2.2Maven
Published Jan 29, 2016
Tracked Since Feb 18, 2026