VYPR

Sentry

by Apache

Source repositories

CVEs (2)

  • CVE-2018-8028HigAug 23, 2018
    risk 0.57cvss 8.8epss 0.01

    An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1. This can allow an attacker unauthorized access to the partitioned data of a Sentry protected table and can allow an attacker to remove data from a Sentry…

  • CVE-2016-0760HigAug 19, 2016
    risk 0.57cvss 8.8epss 0.03

    Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) reflect, (2) reflect2, or (3) java_method Hive builtin functions.