PT-2021-10311 · Apache · Apache Hive

CVE-2020-1926

·

Published

2021-03-16

·

Updated

2022-08-05

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache Hive versions prior to 2.3.8
Description: The issue is related to Apache Hive's cookie signature verification, which used a non-constant time comparison. This comparison is known to be vulnerable to timing attacks, potentially allowing the recovery of another user's cookie signature.
Recommendations: For versions prior to 2.3.8, update to Apache Hive 2.3.8 to address the issue. As a temporary workaround, consider restricting access to sensitive operations that rely on cookie signature verification until the update is applied.

Fix

Information Disclosure

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1926
GHSA-54G4-5CF6-HJP3

Affected Products

Apache Hive