Executive brief
Apache Hive before 3.1.3 `CREATE` and `DROP` function operations do not check for necessary authorization.
Affected products
- Maven org.apache.hive:hive
Junglewise Threat Intelligence
CVE-2021-34538 · Severity: low · CVSS 3.1 · Published 2022-07-17
Technologies: org.apache.hive:hive (Maven). Vendors: Maven.
Apache Hive before 3.1.3 `CREATE` and `DROP` function operations do not check for necessary authorization.