org.apache.hive:hive-hplsql@2.1.0 vulnerabilities
-
latest version
4.0.0
-
latest non vulnerable version
-
first published
8 years ago
-
latest version published
23 days ago
-
licenses detected
- [2.0.0,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the org.apache.hive:hive-hplsql package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
org.apache.hive:hive-hplsql is a data warehouse software facilitates reading, writing, and managing large datasets residing in distributed storage using SQL. Affected versions of this package are vulnerable to Arbitrary File Write via the File Transfer Protocol (FTP) client functionality. Hive gives an SQL-like interface to query data stored in various databases and file systems that integrate with Hadoop. Among other things, it supports copying data from FTP servers, using the COPY-FROM-FTP command.
A possible attack can be overriding the ssh authorized_keys file for the root user, making it possible to login as root later on. Assumming that Apache Hive instance connects to the attacker's malicious FTP server, to download some merchant data daily, by using the following query:
The malicious FTP server would send back path traversal filenames to the client. For instance, responding to a LIST command with When Hive executes the above statement (assuming it’s running as root), root’s How to fix Arbitrary File Write? Upgrade |
[2.1.0,2.3.3)
|