CVE-2021-34538
It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- apache/hive
- Source
- security@apache.org
References
- https://lists.apache.org/thread/oqqgnhz4c6nxsfd0xstosnk0g15f7354Mailing List, Vendor Advisory
- https://lists.apache.org/thread/oqqgnhz4c6nxsfd0xstosnk0g15f7354Mailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.