Apache Sentry may allow attacker to access/remove data from Sentry protected table
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Aug 23, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Nov 22, 2022
Last updated
Feb 2, 2023
An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1. This can allow an attacker unauthorized access to the partitioned data of a Sentry protected table and can allow an attacker to remove data from a Sentry protected table.
References