VulnerabilityModified
CVE-2020-1926
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks.
MEDIUM 5.9EPSS 2.46%
Does this matter?
Lower severity and a low EPSS score (2.46%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.46% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-208, CWE-203
- Affected
- apache/hive
- Source
- security@apache.org
References
- https://issues.apache.org/jira/browse/HIVE-22708Issue Tracking, Patch, Vendor Advisory
- https://lists.apache.org/thread.html/rd186eedff68102ba1e68059a808101c5aa587e11542c7dcd26e7b9d7%40%3Cuser.hive.apache.org%3EMailing List, Patch, Vendor Advisory
- https://issues.apache.org/jira/browse/HIVE-22708Issue Tracking, Patch, Vendor Advisory
- https://lists.apache.org/thread.html/rd186eedff68102ba1e68059a808101c5aa587e11542c7dcd26e7b9d7%40%3Cuser.hive.apache.org%3EMailing List, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.