Security Advisory

CVE-2021-40331

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-05-05 07:55:06
Last updated 2024-10-11 17:07:19
Assigner apache
CVSS score not scored
State PUBLISHED

Description

An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.