{"id":"GHSA-83r3-c79w-f6wc","summary":"High severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service","details":"The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.","aliases":["CVE-2015-7521"],"modified":"2023-11-08T03:58:00.245070Z","published":"2018-11-21T22:23:49Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-287"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:24:07Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7521"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-83r3-c79w-f6wc"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/hive-user/201601.mbox/%3C20160128205008.2154F185EB%40minotaur.apache.org%3E"},{"type":"WEB","url":"http://packetstormsecurity.com/files/135836/Apache-Hive-Authorization-Bypass.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/01/28/12"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/537549/100/0/threaded"}],"affected":[{"package":{"name":"org.apache.hive:hive","ecosystem":"Maven","purl":"pkg:maven/org.apache.hive/hive"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.2.2"}]}],"versions":["1.0.0","1.0.1","1.1.0","1.1.1","1.2.0","1.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/11/GHSA-83r3-c79w-f6wc/GHSA-83r3-c79w-f6wc.json"}},{"package":{"name":"org.apache.hive:hive-exec","ecosystem":"Maven","purl":"pkg:maven/org.apache.hive/hive-exec"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.2.2"}]}],"versions":["1.0.0","1.0.1","1.1.0","1.1.1","1.2.0","1.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/11/GHSA-83r3-c79w-f6wc/GHSA-83r3-c79w-f6wc.json"}},{"package":{"name":"org.apache.hive:hive-service","ecosystem":"Maven","purl":"pkg:maven/org.apache.hive/hive-service"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.2.2"}]}],"versions":["1.0.0","1.0.1","1.1.0","1.1.1","1.2.0","1.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/11/GHSA-83r3-c79w-f6wc/GHSA-83r3-c79w-f6wc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"}]}