GHSA-vjr2-wpfh-5r9p

Suggest an improvement
Source
https://github.com/advisories/GHSA-vjr2-wpfh-5r9p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-vjr2-wpfh-5r9p/GHSA-vjr2-wpfh-5r9p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vjr2-wpfh-5r9p
Aliases
Published
2023-05-05T09:30:15Z
Modified
2024-02-16T08:23:49.077373Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Apache Ranger Hive Plugin missing permissions check
Details

An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.

Database specific
{
    "nvd_published_at": "2023-05-05T08:15:08Z",
    "cwe_ids": [
        "CWE-732"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-05-05T22:53:57Z"
}
References

Affected packages

Maven / org.apache.ranger:ranger-hive-plugin

Package

Name
org.apache.ranger:ranger-hive-plugin
View open source insights on deps.dev
Purl
pkg:maven/org.apache.ranger/ranger-hive-plugin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.4.0

Affected versions

2.*

2.0.0
2.1.0
2.2.0
2.3.0