Medium severity5.5NVD Advisory· Published Jan 28, 2025· Updated Jun 17, 2026
CVE-2024-29869
CVE-2024-29869
Description
Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into this file. Users are recommended to upgrade to version 4.0.1, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.hive:hive-execMaven | < 4.0.1 | 4.0.1 |
Affected products
22- osv-coords20 versionspkg:apk/chainguard/spark-4.1pkg:apk/wolfi/spark-3.5-scala-2.12-compatpkg:apk/wolfi/spark-4.1-scala-2.13-compatpkg:maven/org.apache.hive/hive-execpkg:apk/chainguard/spark-3.5pkg:apk/chainguard/spark-3.5-scala-2.13-compatpkg:apk/chainguard/spark-4.0-scala-2.13-compatpkg:apk/chainguard/spark-fips-3.5pkg:apk/wolfi/spark-4.0-scala-2.13-compatpkg:apk/wolfi/spark-4.1pkg:apk/chainguard/spark-fips-3.5-scala-2.13-compatpkg:apk/wolfi/spark-3.5-scala-2.13-compatpkg:apk/chainguard/spark-4.0pkg:apk/chainguard/spark-4.1-scala-2.13-compatpkg:apk/wolfi/spark-4.0pkg:apk/chainguard/spark-3.5-scala-2.12-iamguarded-compatpkg:apk/chainguard/spark-fips-3.5-scala-2.12-compatpkg:apk/wolfi/spark-3.5pkg:apk/wolfi/spark-3.5-scala-2.12-iamguarded-compatpkg:apk/chainguard/spark-3.5-scala-2.12-compat
< 4.1.0-r1+ 19 more
- (no CPE)range: < 4.1.0-r1
- (no CPE)range: < 3.5.7-r2
- (no CPE)range: < 4.1.0-r1
- (no CPE)range: < 4.0.1
- (no CPE)range: < 3.5.7-r2
- (no CPE)range: < 3.5.7-r2
- (no CPE)range: < 4.0.1-r1
- (no CPE)range: < 3.5.4-r17
- (no CPE)range: < 4.0.1-r1
- (no CPE)range: < 4.1.0-r1
- (no CPE)range: < 3.5.4-r17
- (no CPE)range: < 3.5.7-r2
- (no CPE)range: < 4.0.1-r1
- (no CPE)range: < 4.1.0-r1
- (no CPE)range: < 4.0.1-r1
- (no CPE)range: < 3.5.7-r2
- (no CPE)range: < 3.5.4-r17
- (no CPE)range: < 3.5.7-r2
- (no CPE)range: < 3.5.7-r2
- (no CPE)range: < 3.5.7-r2
Patches
Vulnerability mechanics
References
6- github.com/apache/hive/commit/20106e254527f7d71b2e34455c4322e14950c620nvdPatchWEB
- www.openwall.com/lists/oss-security/2025/01/28/4nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-c476-j253-5rgqghsaADVISORY
- lists.apache.org/thread/h27ohpyrqf9w1m3c0tqr7x8jg59rcrv6nvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-29869ghsaADVISORY
- issues.apache.org/jira/browse/HIVE-28134nvdIssue TrackingWEB
News mentions
0No linked articles in our index yet.