PT-2023-9835 · Apache · Apache Spark+1

Hamza Tahmi

+1

·

Published

2023-10-17

·

Updated

2025-07-14

·

CVE-2024-23945

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Hive versions 1.2.0 and later Apache Spark versions 2.0.0 and later
Description The issue is related to the exposure of digital signatures in cookie data, which can lead to security vulnerabilities and exploitation. The vulnerable CookieSigner logic was introduced in Apache Hive and Apache Spark, allowing malicious actors to modify cookie values. The affected components include org.apache.hive:hive-service, org.apache.spark:spark-hive-thriftserver 2.11, and org.apache.spark:spark-hive-thriftserver 2.12. Exposing the correct cookie signature can lead to further exploitation.
Recommendations For Apache Hive version 1.2.0 and later, update to a version that fixes the vulnerable CookieSigner logic. For Apache Spark version 2.0.0 and later, update to a version that fixes the vulnerable CookieSigner logic. As a temporary workaround, consider disabling the CookieSigner function until a patch is available. Restrict access to the affected components, including org.apache.hive:hive-service, org.apache.spark:spark-hive-thriftserver 2.11, and org.apache.spark:spark-hive-thriftserver 2.12, to minimize the risk of exploitation.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-00249
CVE-2024-23945
GHSA-77PM-W3HX-F8MJ
OESA-2025-1039

Affected Products

Apache Hive
Apache Spark