PT-2018-11631 · Apache · Apache Hive

Danny Grander

·

Published

2018-04-05

·

Updated

2019-10-03

·

CVE-2018-1315

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Hive versions 2.1.0 through 2.3.2
Description The issue arises when the 'COPY FROM FTP' statement is executed using the HPL/SQL extension to Hive. A malicious FTP server can cause a file to be written to an arbitrary location on the cluster, as the FTP client code in HPL/SQL does not verify the destination location of the downloaded file. This issue does not affect Hive CLI users or HiveServer2 users, as HPL/SQL is a separate command-line script invoked differently.
Recommendations For Apache Hive versions 2.1.0 through 2.3.2, consider disabling the HPL/SQL extension until a patch is available to prevent potential exploitation. Restrict access to the 'COPY FROM FTP' statement to minimize the risk of arbitrary file writes on the cluster.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1315
GHSA-P639-XXV5-J383

Affected Products

Apache Hive