Description
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0830 | Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8 |
Github GHSA |
GHSA-54g4-5cf6-hjp3 | Apache Hive Information Exposure and Observable Timing Discrepancy |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:38.760Z
Reserved: 2019-12-02T00:00:00.000Z
Link: CVE-2020-1926
No data.
Status : Modified
Published: 2021-03-16T13:15:11.893
Modified: 2024-11-21T05:11:37.267
Link: CVE-2020-1926
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA