CVE-2017-12625 Information

Description

Apache Hive 2.1.x before 2.1.2 2.2.x before 2.2.1 and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views e.g. using Apache Ranger. When a view is created over a given table the policy enforcement does not happen correctly on the table for masked columns.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Reference

http://mail-archives.apache.org/mod_mbox/hive-user/201710.mbox/3C3791103E-80D5-4E75-AF23-6F8ED54DDEBE40apache.org3E http://www.securityfocus.com/bid/101686

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

NONE

Base Score

NONE

Base Severity

4.3

Share on: