Description
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
Remediation
References
https://issues.apache.org/jira/browse/HIVE-22708
https://lists.apache.org/thread.html/rd186eedff68102ba1e68059a808101c5aa587e11542c7dcd26e7b9d7%40%3Cuser.hive.apache.org%3E
Related Vulnerabilities
CVE-2023-45811 Vulnerability in npm package deobfuscator
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wfs
CVE-2020-6429 Vulnerability in npm package electron
CVE-2020-28267 Vulnerability in npm package @strikeentco/set
CVE-2020-28270 Vulnerability in npm package object-hierarchy-access