AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-34538

HIGH · CVSS 7.5 EPSS 1.65%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-07-16 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects Apache.

CVE
CVE-2021-34538
Severity
HIGH
CVSS
7.5
EPSS
1.65%
Apache

Original NVD Description

Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.

Related CVEs

Other vulnerabilities affecting the same vendor(s)