CVE-2020-1926: Apache Hive
Medium severity, CVSS 5.9. EPSS: 2.5% chance of exploitation in the next 30 days.
Apache Hive cookie signature verification used a non constant time comparison which is known to be vulnerable to timing attacks. This could allow recovery of another users cookie signature. The issue was addressed in Apache Hive 2.3.8
Affected products
- Apache Hive: before 2.3.8 (fixed in 2.3.8)
Published 2021-03-16. Last modified 2026-06-17.