Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:38.760Z
Reserved: 2019-12-02T00:00:00.000Z
Link: CVE-2020-1926

No data.

Status : Modified
Published: 2021-03-16T13:15:11.893
Modified: 2024-11-21T05:11:37.267
Link: CVE-2020-1926

No data.