Apache Hive における証明書検証に関する脆弱性
| Title |
Apache Hive における証明書検証に関する脆弱性
|
| Summary |
Apache Hive (JDBC + HiveServer2) には、証明書検証に関する脆弱性が存在します。
|
| Possible impacts |
情報を改ざんされる可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
March 10, 2016, midnight |
| Registration Date |
June 20, 2017, 1:57 p.m. |
| Last Update |
June 20, 2017, 1:57 p.m. |
|
CVSS3.0 : 重要
|
| Score |
7.5
|
| Vector |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
|
CVSS2.0 : 警告
|
| Score |
5
|
| Vector |
AV:N/AC:L/Au:N/C:N/I:P/A:N |
Affected System
| Apache Software Foundation |
|
Apache Hive 1.2.2 未満
|
|
Apache Hive 2.0.1 未満の 2.0.x
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
Change Log
| No |
Changed Details |
Date of change |
| 0 |
[2017年06月20日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
NVD Vulnerability Information
CVE-2016-3083
| Summary |
Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificate during the connection setup, the client in Apache Hive before 1.2.2 and 2.0.x before 2.0.1 doesn't seem to be verifying the common name attribute of the certificate. In this way, if a JDBC client sends an SSL request to server abc.com, and the server responds with a valid certificate (certified by CA) but issued to xyz.com, the client will accept that as a valid certificate and the SSL handshake will go through.
|
| Publication Date |
May 30, 2017, 11:29 p.m. |
| Registration Date |
Jan. 26, 2021, 2:10 p.m. |
| Last Update |
Nov. 21, 2024, 11:49 a.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:apache:hive:0.13.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:apache:hive:1.1.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:apache:hive:1.1.0:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:apache:hive:1.0.0:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:apache:hive:1.2.0:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:apache:hive:0.14.0:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:apache:hive:1.2.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:apache:hive:1.0.1:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:apache:hive:0.13.0:*:*:*:*:*:*:* |
|
|
|
|
Related information, measures and tools
Common Vulnerabilities List