CVE-2018-1314
08.11.2018, 14:29
In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.Enginsight
Vendor | Product | Version |
---|---|---|
apache | hive | 𝑥 ≤ 2.3.3 |
apache | hive | 3.0.0 ≤ 𝑥 ≤ 3.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References