Loading HuntDB...

GHSA-vjr2-wpfh-5r9p

GitHub Security Advisory

Apache Ranger Hive Plugin missing permissions check

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled
This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.

Affected Packages

Maven org.apache.ranger:ranger-hive-plugin
Affected versions: 2.0.0 (fixed in 2.4.0)

Related CVEs

Key Information

GHSA ID
GHSA-vjr2-wpfh-5r9p
Published
May 5, 2023 9:30 AM
Last Modified
May 11, 2023 8:56 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.ranger:ranger-hive-plugin
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.