{"id":"GHSA-54g4-5cf6-hjp3","summary":"Apache Hive Information Exposure and Observable Timing Discrepancy","details":"Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8","aliases":["CVE-2020-1926"],"modified":"2023-11-08T04:02:45.499739Z","published":"2022-02-09T00:48:54Z","database_specific":{"github_reviewed_at":"2021-03-31T21:30:08Z","nvd_published_at":"2021-03-16T13:15:00Z","cwe_ids":["CWE-200","CWE-203","CWE-208"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-1926"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/HIVE-22708"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rd186eedff68102ba1e68059a808101c5aa587e11542c7dcd26e7b9d7%40%3Cuser.hive.apache.org%3E"}],"affected":[{"package":{"name":"org.apache.hive:hive","ecosystem":"Maven","purl":"pkg:maven/org.apache.hive/hive"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.8"}]}],"versions":["0.13.0","0.13.1","0.14.0","1.0.0","1.0.1","1.1.0","1.1.1","1.2.0","1.2.1","1.2.2","2.0.0","2.0.1","2.1.0","2.1.1","2.2.0","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-54g4-5cf6-hjp3/GHSA-54g4-5cf6-hjp3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}