Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 4 Aug 2016 16:27:12 -0700
From: Sravya Tirukkovalur <sravya@...che.org>
To: dev <dev@...try.apache.org>, security@...che.org, 
	oss-security@...ts.openwall.com, bugtraq@...urityfocus.com
Subject: CVE-2016-0760: Hive builtin functions “reflect”,
	 “reflect2”, and “java_method” are not blocked in Ap
	ache Sentry

CVE-2016-0760: Hive builtin functions “reflect”, “reflect2”, and
“java_method” are not blocked in Apache Sentry

Severity: Very Important

Vendor:
The Apache Software Foundation

Versions Affected:
Sentry 1.5.1 and 1.6.0

Description:
Some functions in Hive which allow arbitrary code to be executed are
not blacklisted properly in some versions of Sentry, which would allow
authenticated
users to potentially use these functions for malicious purposes.

Mitigation:
Upgrade to 1.7.0 (or)
Workaround - Users can explicitly configure the blacklist
functions in the hive configuration by setting the property
"hive.server2.builtin.udf.blacklist" to "reflect,reflect2,java_method"

Credit:
This issue was discovered by Ryan Pridgeon of Cloudera.

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ