CVE-2015-7521

HIGH

Apache Hive <1.3 - Auth Bypass

Title source: llm

Description

The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.

Scores

CVSS v3 8.3
EPSS 0.0040
EPSS Percentile 60.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Classification

CWE
CWE-287
Status draft

Affected Products (8)

apache/hive
apache/hive
apache/hive
apache/hive
apache/hive
org.apache.hive/hive < 1.2.2Maven
org.apache.hive/hive-exec < 1.2.2Maven
org.apache.hive/hive-service < 1.2.2Maven

Timeline

Published Jan 29, 2016
Tracked Since Feb 18, 2026