PT-2026-81255 · Apache · Apache Hive
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Hive versions 4.0.0 through 4.2.0
Description
Improper authentication occurs during SAML bearer-token validation in HiveServer2 on deployments using HTTP transport with
hive.server2.authentication=SAML. An unauthenticated network attacker can authenticate as an arbitrary Hive user and obtain an authenticated HiveServer2 session by sending a forged Authorization: Bearer token to the /cliservice HTTP endpoint. This exploit requires no Hive credentials, SAML Identity Provider (IdP) login, or knowledge of the server signing secret, requiring only network reachability to the HiveServer2 HTTP port.Recommendations
Upgrade to version 4.2.1.
Exploit
Fix
Insufficient Verification of Data Authenticity
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Hive