CVE-2024-23953

Description

A flaw was found in Apache Hive. This vulnerability allows an attacker to forge valid signatures for arbitrary messages byte by byte, potentially enabling denial of service (DDoS) attacks via the use of a timing-based attack exploiting the non-constant time comparison in Arrays.equals(). The attacker must be an authorized user of the product to exploit this issue.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Confidentiality,Access Control

Technical Impact: Read Application Data; Bypass Protection Mechanism

Frequently Asked Questions

Want to get errata notifications? Sign up here.