GHSA-5gvm-hrw5-h6xf

Suggest an improvement
Source
https://github.com/advisories/GHSA-5gvm-hrw5-h6xf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-5gvm-hrw5-h6xf/GHSA-5gvm-hrw5-h6xf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5gvm-hrw5-h6xf
Aliases
  • CVE-2015-1772
Published
2019-03-14T15:40:44Z
Modified
2023-11-08T03:57:50.261758Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Improper Authentication in org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
Details

The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.

Database specific
{
    "nvd_published_at": null,
    "github_reviewed_at": "2020-06-16T21:16:15Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-287"
    ]
}
References

Affected packages

Maven / org.apache.hive:hive

Package

Name
org.apache.hive:hive
View open source insights on deps.dev
Purl
pkg:maven/org.apache.hive/hive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.1

Affected versions

1.*

1.0.0

Maven / org.apache.hive:hive

Package

Name
org.apache.hive:hive
View open source insights on deps.dev
Purl
pkg:maven/org.apache.hive/hive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.1

Affected versions

1.*

1.1.0

Maven / org.apache.hive:hive-exec

Package

Name
org.apache.hive:hive-exec
View open source insights on deps.dev
Purl
pkg:maven/org.apache.hive/hive-exec

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.1

Affected versions

1.*

1.0.0

Maven / org.apache.hive:hive-exec

Package

Name
org.apache.hive:hive-exec
View open source insights on deps.dev
Purl
pkg:maven/org.apache.hive/hive-exec

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.1

Affected versions

1.*

1.1.0

Maven / org.apache.hive:hive-service

Package

Name
org.apache.hive:hive-service
View open source insights on deps.dev
Purl
pkg:maven/org.apache.hive/hive-service

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.1

Affected versions

1.*

1.0.0

Maven / org.apache.hive:hive-service

Package

Name
org.apache.hive:hive-service
View open source insights on deps.dev
Purl
pkg:maven/org.apache.hive/hive-service

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.1

Affected versions

1.*

1.1.0