CVE-2018-8028

HIGH

Apache Sentry <2.0.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1. This can allow an attacker unauthorized access to the partitioned data of a Sentry protected table and can allow an attacker to remove data from a Sentry protected table.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0013
EPSS Percentile 31.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (2)
apache/sentry < 2.0.1
org.apache.sentry/sentry 0 - 2.0.1Maven
Published Aug 23, 2018
Tracked Since Feb 18, 2026