CVE-2017-12625
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcement does not happen correctly on the table for masked columns.
Apache Hive, en versiones 2.1.x anteriores a la 2.1.2, versiones 2.2.x anteriores a la 2.2.1 y versiones 2.3.x anteriores a la 2.3.1 expone una interfaz en la que las polĂticas de enmascaramiento pueden definirse en tablas o vistas. Por ejemplo, utilizando Apache Ranger. Cuando se crea una vista en una determinada tabla, no se lleva a cabo correctamente el cumplimiento de polĂticas en la tabla para las columnas enmascaradas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-07 CVE Reserved
- 2017-11-01 CVE Published
- 2023-09-11 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101686 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Hive Search vendor "Apache" for product "Hive" | 2.1.0 Search vendor "Apache" for product "Hive" and version "2.1.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hive Search vendor "Apache" for product "Hive" | 2.1.1 Search vendor "Apache" for product "Hive" and version "2.1.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hive Search vendor "Apache" for product "Hive" | 2.2.0 Search vendor "Apache" for product "Hive" and version "2.2.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Hive Search vendor "Apache" for product "Hive" | 2.3.0 Search vendor "Apache" for product "Hive" and version "2.3.0" | - |
Affected
|