Description
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.
Remediation
References
https://lists.apache.org/thread/oqqgnhz4c6nxsfd0xstosnk0g15f7354
Related Vulnerabilities
CVE-2023-26473 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2019-16564 Vulnerability in maven package com.paul8620.jenkins.plugins:pipeline-aggregator-view
CVE-2019-10423 Vulnerability in maven package com.villagechief.codescan.jenkins:codescan
CVE-2023-45133 Vulnerability in maven package org.webjars.npm:babel__traverse
CVE-2019-0193 Vulnerability in maven package org.apache.solr:solr-dataimporthandler