PT-2018-18393 · Apache · Apache Sentry
Publicado
2018-08-23
·
Atualizado
2022-05-13
·
CVE-2018-8028
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Apache Sentry versions prior to 2.0.1
Description:
The issue allows an authenticated user to execute ALTER TABLE EXCHANGE PARTITIONS without proper authorization. This can lead to unauthorized access to partitioned data in a Sentry protected table and potentially allow an attacker to remove data from the table.
Recommendations:
For versions prior to 2.0.1, update to version 2.0.1 or later to resolve the issue.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Sentry