GHSA-jmf4-pq78-f8vj
MODERATECVE-2018-1314In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.
- Affected
- >= 3.0.0, < 3.1.1
- Fixed in
- 3.1.1
- Published
- 2018-11-21
- Source
- github