GHSA-54g4-5cf6-hjp3
GitHub Security Advisory
Apache Hive Information Exposure and Observable Timing Discrepancy
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
Affected Packages
Maven
org.apache.hive:hive
Affected versions:
0
(fixed in 2.3.8)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 10, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.