Back to search
CVE-2020-1926
Published: Mar 16, 2021
Modified: Feb 13, 2025
PUBLISHED
Description
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Hive | affected Apache Hive - < 2.3.8 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now