CVE-2015-7521

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
29/01/2016
Last modified:
12/04/2025

Description

The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:hive:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:hive:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:hive:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:hive:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:hive:1.2.1:*:*:*:*:*:*:*