Description
An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1. This can allow an attacker unauthorized access to the partitioned data of a Sentry protected table and can allow an attacker to remove data from a Sentry protected table.
Remediation
References
https://cwiki.apache.org/confluence/display/SENTRY/Vulnerabilities+found+in+Apache+Sentry
Related Vulnerabilities
CVE-2020-27223 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2016-10735 Vulnerability in maven package org.ow2.jonas:bootstrap
CVE-2020-7784 Vulnerability in npm package ts-process-promises
CVE-2022-33891 Vulnerability in maven package org.apache.spark:spark-core_2.13
CVE-2020-2126 Vulnerability in maven package com.dubture.jenkins:digitalocean-plugin