CVE-2021-40331
published 2023-05-05CVE-2021-40331: An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database…
PriorityP348high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.92%
56.2th percentile
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled
This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ranger | 2.0.0 – 2.3.0 | — |
| apache_software_foundation | apache_ranger_hive_plugin | 2.0.0 – 2.3.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Ranger Hive Plugin missing permissions check
osv·2023-05-05
CVE-2021-40331 [HIGH] Apache Ranger Hive Plugin missing permissions check
Apache Ranger Hive Plugin missing permissions check
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled
This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.
GHSA
Apache Ranger Hive Plugin missing permissions check
ghsa·2023-05-05
CVE-2021-40331 [HIGH] CWE-732 Apache Ranger Hive Plugin missing permissions check
Apache Ranger Hive Plugin missing permissions check
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled
This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-05
Published