CVE-2017-12625
Dashboard / Vulnerabilities / CVE-2017-12625
Summary:
Details: Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcement does not happen correctly on the table for masked columns.
References: http://mail-archives.apache.org/mod_mbox/hive-user/201710.mbox/%3C3791103E-80D5-4E75-AF23-6F8ED54DDEBE%40apache.org%3E, http://www.securityfocus.com/bid/101686
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 9265bc24d75ac945bde9ce1a0999fddd8f2aae29
Fixed -None
Affected versions
2.1.0
2.1.1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
