Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2021-03-16T13:00:16
Updated: 2024-08-04T06:54:00.358Z
Reserved: 2019-12-02T00:00:00
Link: CVE-2020-1926
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-03-16T13:15:11.893
Modified: 2024-11-21T05:11:37.267
Link: CVE-2020-1926
Redhat
No data.