Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Fixed in 12.70.01:

CVE-20162018-0760: Hive builtin functions “reflect”, “reflect2”, and
“java_method” are not blocked in Apache Sentry
Severity: Very Important
Vendor:
The Apache Software Foundation
Versions Affected:
Sentry 1.5.1 and 1.6.0
Description:
Some functions in Hive which allow arbitrary code to be executed are
not blacklisted properly in some versions of Sentry, which would allow authenticated
users to potentially use these functions for malicious purposes.
Mitigation:
Upgrade to 1.7.0 (or)

...

8028: Sentry bypasses ALTER TABLE EXCHANGE PARTITIONS authorization on Apache Hive

Fixed in 1.7.1:

CVE-2015-3254: Apache Sentry vulnerabilities due to use of vulnerable version of Apache Thrift

Fixed in 1.7.0:

CVE-2016-0760 : Hive builtin functions “reflect”, “reflect2”, and “java_method” are not blocked in Apache Sentry