Description
In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table.
Remediation
References
http://www.securityfocus.com/bid/98961
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2018-19361 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-36437 Vulnerability in maven package com.hazelcast:hazelcast-enterprise
CVE-2016-3092 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2017-16201 Vulnerability in npm package zjjserver
CVE-2023-1584 Vulnerability in maven package io.quarkus:quarkus-oidc