CVE-2017-12625
Last modified
CVE-2017-12625 is a vulnerability of currently unknown severity. Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcement does not happen correctly on the table for masked columns.. EPSS estimates a 1.43% chance of exploitation in the next 30 days.
Description
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcement does not happen correctly on the table for masked columns.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Hive | 2.1.0 |
| Apache | Hive | 2.1.1 |
| Apache | Hive | 2.2.0 |
| Apache | Hive | 2.3.0 |
References
- http://www.securityfocus.com/bid/101686Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/101686Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12625?
How severe is CVE-2017-12625?
How do I fix CVE-2017-12625?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-1262IBM Security Guardium 10.0 is vulnerable to HTTP response sp…
- CVE-2017-12620When loading models or dictionaries that contain XML it is p…
- CVE-2017-12621During Jelly (xml) file parsing with Apache Xerces, if a cus…9.8
- CVE-2017-12622When an Apache Geode cluster before v1.3.0 is operating in s…
- CVE-2017-12623An authorized user could upload a template which contained m…
- CVE-2017-12624Apache CXF supports sending and receiving attachments via ei…
- CVE-2017-12626Apache POI in versions prior to release 3.17 are vulnerable …7.5
- CVE-2017-12627In Apache Xerces-C XML Parser library before 3.2.1, processi…
- CVE-2017-12628The JMX server embedded in Apache James, also used by the co…
- CVE-2017-12629Remote code execution occurs in Apache Solr before 7.1 with …9.8
- CVE-2017-12630In Apache Drill 1.11.0 and earlier when submitting form from…
- CVE-2017-12631Apache CXF Fediz ships with a number of container-specific p…
Are you affected by CVE-2017-12625?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
