Exposure of Sensitive Information to an Unauthorized Actor in Apache hive
Low severity
GitHub Reviewed
Published
Nov 21, 2018
to the GitHub Advisory Database
•
Updated Mar 4, 2024
Description
Published to the GitHub Advisory Database
Nov 21, 2018
Reviewed
Jun 16, 2020
Last updated
Mar 4, 2024
In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveServer2 user (usually hive) if hive.server2.enable.doAs=false.
References