Executive brief
Apache Hive is a data warehouse software used to query and analyze large datasets in Hadoop clusters. HiveServer2 is the server component that accepts client connections via HTTP. A flaw in SAML bearer-token validation allows unauthenticated attackers to forge authentication tokens and gain arbitrary user access to the system without credentials, potentially exposing sensitive data and enabling unauthorized data manipulation.
Technical details
This is an improper authentication vulnerability in HiveServer2's SAML bearer-token validation mechanism. The vulnerability exists when HiveServer2 is configured to use HTTP transport with SAML authentication enabled. An unauthenticated network attacker can craft a forged Authorization: Bearer token and send it to the /cliservice HTTP endpoint to authenticate as an arbitrary Hive user without possessing valid SAML IdP credentials or knowledge of the server's signing secret. Attack requires only network reachability to HiveServer2's HTTP port (typically port 10000) and applies to deployments using native SAML mode on HTTP; LDAP/Kerberos and reverse proxy configurations like Knox with SSO are unaffected. Affected versions are 4.0.0 through 4.2.0 and later unreleased branches; the fix is available in version 4.2.1.
Affected products
- Apache Hive 4.0.0 through 4.2.0 and later unreleased branches
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fix available in version 4.2.1