PT-2017-12609 · Apache · Apache Ranger+1
Published
2017-11-01
·
Updated
2019-03-14
·
CVE-2017-12625
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Hive versions 2.1.x through 2.1.2
Apache Hive versions 2.2.x through 2.2.1
Apache Hive versions 2.3.x through 2.3.1
Description
The issue arises when a view is created over a table, and policy enforcement for masked columns does not occur correctly on the table. This is related to the interface that allows defining masking policies on tables or views, such as through Apache Ranger.
Recommendations
For Apache Hive versions 2.1.x through 2.1.2, update to version 2.1.2 or later.
For Apache Hive versions 2.2.x through 2.2.1, update to version 2.2.1 or later.
For Apache Hive versions 2.3.x through 2.3.1, update to version 2.3.1 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Hive
Apache Ranger