Severity: important

Affected versions:

- Apache Hive 1.1.0 before 4.0.1

Description:

Hive creates a credentials file to a temporary directory in the file system 
with permissions 644 by default when the file permissions are not set 
explicitly. Any unauthorized user having access to the directory can read the 
sensitive information written into this file. Users are recommended to upgrade 
to version 4.0.1, which fixes this issue.

Credit:

Andrea Cosentino (reporter)

References:

https://github.com/apache/hive
https://github.com/apache/hive/commit/20106e254527f7d71b2e34455c4322e14950c620
https://issues.apache.org/jira/browse/HIVE-28134
https://hive.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-29869

Reply via email to