Description
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
Remediation
References
https://issues.apache.org/jira/browse/HIVE-22708
https://lists.apache.org/thread.html/rd186eedff68102ba1e68059a808101c5aa587e11542c7dcd26e7b9d7%40%3Cuser.hive.apache.org%3E
Related Vulnerabilities
CVE-2016-10707 Vulnerability in maven package org.webjars:jquery
CVE-2021-29486 Vulnerability in npm package cumulative-distribution-function
CVE-2020-10748 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2022-31129 Vulnerability in maven package org.webjars:momentjs
CVE-2017-15010 Vulnerability in maven package org.webjars.npm:tough-cookie