ZeroHour

CVE-2020-1926

CVSS 3.1
5.9 medium
EPSS
2%p83
Published
()
Modified
Description

Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8

Vendors
apache
Products
hive
Weakness
CWE-208, CWE-203
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.