CVE-2021-34538

CVE-2021-34538: Apache Hive Security vulnerability in Hive with UDFs

Vendor Apache Software Foundation
Product Apache Hive
Weakness CWE-306 · Missing auth
Published July 16, 2022
Last update August 4, 2024

CVSS base score

What the vulnerability does

Description

Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.

Key dates

Disclosure timeline

July 16, 2022 CVE published
August 4, 2024 Record updated