Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-0830 | Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8 |
![]() |
GHSA-54g4-5cf6-hjp3 | Apache Hive Information Exposure and Observable Timing Discrepancy |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:38.760Z
Reserved: 2019-12-02T00:00:00.000Z
Link: CVE-2020-1926

No data.

Status : Modified
Published: 2021-03-16T13:15:11.893
Modified: 2024-11-21T05:11:37.267
Link: CVE-2020-1926

No data.

No data.