CVE-2021-40331

CVE-2021-40331: Permissions problem in the Apache Ranger Hive Plugin

Vendor Apache Software Foundation
Product Apache Ranger Hive Plugin
Weakness CWE-732
Published May 5, 2023
Last update October 11, 2024

CVSS base score

What the vulnerability does

Description

An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.

Key dates

Disclosure timeline

May 5, 2023 CVE published
October 11, 2024 Record updated