|
Message-ID: <CACMN7ixDqDyOZGLEvsMUVHBiJ6crq8zdy+2mNfRooNhnk7CJ1g@mail.gmail.com> Date: Thu, 4 Aug 2016 16:27:12 -0700 From: Sravya Tirukkovalur <sravya@...che.org> To: dev <dev@...try.apache.org>, security@...che.org, oss-security@...ts.openwall.com, bugtraq@...urityfocus.com Subject: CVE-2016-0760: Hive builtin functions “reflect”, “reflect2”, and “java_method” are not blocked in Apache Sentry CVE-2016-0760: Hive builtin functions “reflect”, “reflect2”, and “java_method” are not blocked in Apache Sentry Severity: Very Important Vendor: The Apache Software Foundation Versions Affected: Sentry 1.5.1 and 1.6.0 Description: Some functions in Hive which allow arbitrary code to be executed are not blacklisted properly in some versions of Sentry, which would allow authenticated users to potentially use these functions for malicious purposes. Mitigation: Upgrade to 1.7.0 (or) Workaround - Users can explicitly configure the blacklist functions in the hive configuration by setting the property "hive.server2.builtin.udf.blacklist" to "reflect,reflect2,java_method" Credit: This issue was discovered by Ryan Pridgeon of Cloudera.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.