CVE-2021-34538
HIGHApache Hive < 3.1.3 - Missing Authentication
Title source: ruleDescription
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.
Scores
CVSS v3
7.5
EPSS
0.0030
EPSS Percentile
52.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-306
Status
published
Affected Products (2)
apache/hive
< 3.1.3
org.apache.hive/hive
< 3.1.3Maven
Timeline
Published
Jul 16, 2022
Tracked Since
Feb 18, 2026