Description
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
Remediation
References
https://issues.apache.org/jira/browse/HIVE-22708
https://lists.apache.org/thread.html/rd186eedff68102ba1e68059a808101c5aa587e11542c7dcd26e7b9d7%40%3Cuser.hive.apache.org%3E
Related Vulnerabilities
CVE-2018-11694 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2021-3163 Vulnerability in npm package quill
CVE-2023-31579 Vulnerability in maven package top.tangyh.basic:lamp-util
CVE-2022-24785 Vulnerability in maven package org.webjars.npm:moment
CVE-2023-30331 Vulnerability in maven package com.ibeetl:beetl