Apache Hive Incorrectly Assigns Permissions for a Critical Resource
Moderate severity
GitHub Reviewed
Published
Jan 29, 2025
to the GitHub Advisory Database
•
Updated Jan 29, 2025
Description
Published by the National Vulnerability Database
Jan 28, 2025
Published to the GitHub Advisory Database
Jan 29, 2025
Last updated
Jan 29, 2025
Reviewed
Jan 29, 2025
Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into this file. Users are recommended to upgrade to version 4.0.1, which fixes this issue.
References