Apache Hive
cpe:2.3:a:apache:hive:*:*:*:*:*:*:*
- >= 1.1.0, < 4.0.1
A vulnerability exists in Apache Hive versions 1.1.0 prior to 4.0.1, where a credentials file is created in a temporary directory with default permissions of 644. This allows any unauthorized user with access to the directory to read the sensitive information in the file. The issue arises because the file permissions are not explicitly set, leaving the credentials exposed to unauthorized access.
The vulnerability allows unauthorized users to read sensitive information from the credentials file.
Users are advised to upgrade to Apache Hive version 4.0.1, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.