3.7
CVSSv3

CVE-2018-1284

Published: 05/04/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 3.7 | Impact Score: 1.4 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveServer2 user (usually hive) if hive.server2.enable.doAs=false.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache hive

Vendor Advisories

In Apache Hive 060 to 232, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveServer2 user (usually hive) if hiveserver2enabledoAs=false ...

Github Repositories

Hive UDFs for funnel analysis

Hive Funnel Analysis UDFs Funnel analysis is a method for tracking user conversion rates across actions This enables detection of actions causing high user fallout These Hive UDFs enables funnel analysis to be performed simply and easily on any Hive table Table of Contents Requirements How to build Build JAR Register JAR with Hive How to use funnel funnel_merge funne