PT-2021-10311 · Apache · Apache Hive

Published

2021-03-16

·

Updated

2022-08-05

·

CVE-2020-1926

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache Hive versions prior to 2.3.8
Description: The issue is related to Apache Hive's cookie signature verification, which used a non-constant time comparison. This comparison is known to be vulnerable to timing attacks, potentially allowing the recovery of another user's cookie signature.
Recommendations: For versions prior to 2.3.8, update to Apache Hive 2.3.8 to address the issue. As a temporary workaround, consider restricting access to sensitive operations that rely on cookie signature verification until the update is applied.

Fix

Information Disclosure

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2020-1926
GHSA-54G4-5CF6-HJP3

Affected Products

Apache Hive