Description
In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table.
Remediation
References
http://www.securityfocus.com/bid/98961
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2022-34114 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2017-16057 Vulnerability in npm package nodemssql
CVE-2014-3623 Vulnerability in maven package org.apache.cxf:cxf-rt-ws-security
CVE-2021-21479 Vulnerability in maven package com.sap.scimono:scimono-server
CVE-2022-22885 Vulnerability in maven package cn.hutool:hutool-http