CVE-2018-1315
LOWApache Hive < 2.3.2 - Incorrect Permission Assignment
Title source: ruleDescription
In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statement is run using HPL/SQL extension to Hive, a compromised/malicious FTP server can cause the file to be written to an arbitrary location on the cluster where the command is run from. This is because FTP client code in HPL/SQL does not verify the destination location of the downloaded file. This does not affect hive cli user and hiveserver2 user as hplsql is a separate command line script and needs to be invoked differently.
Scores
CVSS v3
3.7
EPSS
0.0103
EPSS Percentile
77.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-732
Status
published
Affected Products (4)
apache/hive
< 2.3.2
org.apache.hive/hive
< 2.3.3Maven
org.apache.hive/hive-exec
< 2.3.3Maven
org.apache.hive/hive-service
< 2.3.3Maven
Timeline
Published
Apr 05, 2018
Tracked Since
Feb 18, 2026