PT-2021-10311 · Apache · Apache Hive
Published
2021-03-16
·
Updated
2022-08-05
·
CVE-2020-1926
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Hive versions prior to 2.3.8
Description:
The issue is related to Apache Hive's cookie signature verification, which used a non-constant time comparison. This comparison is known to be vulnerable to timing attacks, potentially allowing the recovery of another user's cookie signature.
Recommendations:
For versions prior to 2.3.8, update to Apache Hive 2.3.8 to address the issue. As a temporary workaround, consider restricting access to sensitive operations that rely on cookie signature verification until the update is applied.
Fix
Information Disclosure
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Hive