← Back to CVEs
CVE-2020-1926
MEDIUM5.9
Description
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
CVE Details
CVSS v3.1 Score5.9
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
Published3/16/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
apache:hive
Weaknesses (CWE)
CWE-208CWE-203
References
https://issues.apache.org/jira/browse/HIVE-22708(security@apache.org)
https://lists.apache.org/thread.html/rd186eedff68102ba1e68059a808101c5aa587e11542c7dcd26e7b9d7%40%3Cuser.hive.apache.org%3E(security@apache.org)
https://issues.apache.org/jira/browse/HIVE-22708(af854a3a-2127-422b-91ae-364da2661108)
https://lists.apache.org/thread.html/rd186eedff68102ba1e68059a808101c5aa587e11542c7dcd26e7b9d7%40%3Cuser.hive.apache.org%3E(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.