CVE-2018-11777

HIGH

Apache Hive <2.3.3, <3.1.0 - Info Disclosure

Title source: llm

Description

In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.

Scores

CVSS v3 8.1
EPSS 0.0041
EPSS Percentile 61.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Classification

Status published

Affected Products (2)

apache/hive < 2.3.3
org.apache.hive/hive-exec < 3.1.1Maven

Timeline

Published Nov 08, 2018
Tracked Since Feb 18, 2026