CVE-2021-34538 - CVE House
Back to Database
Status published High CVE-2021-34538

Apache Hive Security vulnerability in Hive with UDFs

Vulnerability Description

Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-34538

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This vulnerability was discovered and reported by Hideyuki Furue.

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Hive
Vulnerable Versions:
Apache Hive

Timeline

Official Publish: July 16th, 2022
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses (CWE)