SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-34538

It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so.

HIGH 7.5EPSS 1.76%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
1.76% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
apache/hive
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.